Description
Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/04/12/2
http://www.securityfocus.com/bid/107790
https://jenkins.io/security/advisory/2019-04-03/#SECURITY-1090
Related Vulnerabilities
CVE-2017-10355 Vulnerability in maven package xerces:xercesimpl
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-trino
CVE-2021-23378 Vulnerability in npm package picotts
CVE-2023-3691 Vulnerability in maven package org.webjars.npm:layui
CVE-2020-2143 Vulnerability in maven package org.jenkins-ci.plugins:logstash