Description
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992
Related Vulnerabilities
CVE-2021-21351 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-10787 Vulnerability in npm package im-resize
CVE-2023-30514 Vulnerability in maven package org.jenkins-ci.plugins:azure-keyvault
CVE-2020-13410 Vulnerability in npm package aedes
CVE-2022-45391 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration