Description
Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1044
Related Vulnerabilities
CVE-2023-26155 Vulnerability in npm package node-qpdf
CVE-2020-7730 Vulnerability in npm package bestzip
CVE-2022-25927 Vulnerability in npm package ua-parser-js
CVE-2019-1003060 Vulnerability in maven package org.jenkins-ci.plugins:zap
CVE-2015-8861 Vulnerability in maven package org.webjars.npm:handlebars