Description
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992
Related Vulnerabilities
CVE-2019-14862 Vulnerability in npm package knockout
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2021-25642 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-resourcemanager
CVE-2020-36632 Vulnerability in maven package org.webjars.npm:flat