Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.securityfocus.com/bid/108045
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
Related Vulnerabilities
CVE-2021-21626 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2022-34112 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2014-0363 Vulnerability in maven package org.igniterealtime.smack:smack-core
CVE-2022-30618 Vulnerability in npm package strapi
CVE-2018-12538 Vulnerability in maven package org.eclipse.jetty:jetty-server