Description
Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/11/4
http://www.securityfocus.com/bid/109156
https://jenkins.io/security/advisory/2019-07-11/#SECURITY-1441
https://www.zerodayinitiative.com/advisories/ZDI-19-838/
Related Vulnerabilities
CVE-2022-45384 Vulnerability in maven package org.jenkins-ci.plugins:reverse-proxy-auth-plugin
CVE-2022-38666 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2022-45388 Vulnerability in maven package net.praqma:config-rotator
CVE-2019-9843 Vulnerability in maven package com.diffplug.spotless:spotless-plugin-gradle
CVE-2021-4329 Vulnerability in maven package org.webjars.npm:json-logic-js