Description
Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1040
http://www.securityfocus.com/bid/107790
http://www.openwall.com/lists/oss-security/2019/04/12/2
Related Vulnerabilities
CVE-2015-8855 Vulnerability in npm package semver
CVE-2022-36527 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2023-25768 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials
CVE-2022-22968 Vulnerability in maven package org.springframework:spring-context
CVE-2018-1999047 Vulnerability in maven package org.jenkins-ci.main:jenkins-core