Description
Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1041
http://www.securityfocus.com/bid/107790
http://www.openwall.com/lists/oss-security/2019/04/12/2
Related Vulnerabilities
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-dao
CVE-2016-0781 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2018-14042 Vulnerability in maven package org.webjars:bootstrap
CVE-2014-0227 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2023-4302 Vulnerability in maven package org.jenkins-ci.plugins:fortify