Description
Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-04-17/#SECURITY-844
http://www.securityfocus.com/bid/108045
Related Vulnerabilities
CVE-2023-2633 Vulnerability in maven package org.jenkins-ci.plugins:codedx
CVE-2023-46998 Vulnerability in maven package org.webjars.bowergithub.makeusabrew:bootbox
CVE-2022-25931 Vulnerability in npm package easy-static-server
CVE-2019-1003050 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-1415 Vulnerability in maven package org.drools:drools-core