Description
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992
Related Vulnerabilities
CVE-2022-32533 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed
CVE-2021-41862 Vulnerability in maven package com.googlecode.aviator:aviator
CVE-2022-41946 Vulnerability in maven package org.postgresql:postgresql
CVE-2018-1000644 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-rio-rdfxml
CVE-2019-10095 Vulnerability in maven package org.apache.zeppelin:zeppelin