Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2018-1114 Vulnerability in maven package io.undertow:undertow-core
CVE-2019-10768 Vulnerability in maven package org.webjars.npm:angular
CVE-2017-16174 Vulnerability in npm package whispercast
CVE-2019-1003077 Vulnerability in maven package org.jenkins-ci.plugins:audit2db
CVE-2017-18353 Vulnerability in npm package rendertron-middleware