Description
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/12/2
https://jenkins.io/security/advisory/2019-09-12/#SECURITY-1545
Related Vulnerabilities
CVE-2019-14900 Vulnerability in maven package org.hibernate:hibernate-core
CVE-2022-24719 Vulnerability in npm package fluture-node
CVE-2022-31170 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2022-32549 Vulnerability in maven package org.apache.sling:org.apache.sling.api
CVE-2022-41853 Vulnerability in maven package org.hsqldb:hsqldb