Description
Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1575
Related Vulnerabilities
CVE-2021-28092 Vulnerability in maven package org.webjars.npm:is-svg
CVE-2020-10758 Vulnerability in maven package org.keycloak:keycloak-wildfly-server-subsystem
CVE-2020-6460 Vulnerability in npm package electron
CVE-2022-46175 Vulnerability in npm package json5
CVE-2020-7633 Vulnerability in npm package apiconnect-cli-plugins