Description
Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2944
Related Vulnerabilities
CVE-2023-24831 Vulnerability in maven package org.apache.iotdb:iotdb-grafana-connector
CVE-2022-43419 Vulnerability in maven package org.jenkins-ci.plugins:katalon
CVE-2020-1745 Vulnerability in maven package io.undertow:undertow-core
CVE-2020-7637 Vulnerability in maven package org.webjars.npm:class-transformer
CVE-2020-15087 Vulnerability in maven package io.prestosql:presto-main