Description
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1504
Related Vulnerabilities
CVE-2023-26049 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2020-11022 Vulnerability in maven package org.webjars.npm:jquery
CVE-2022-4137 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2022-42130 Vulnerability in maven package com.liferay:com.liferay.dynamic.data.mapping.service
CVE-2018-8041 Vulnerability in maven package org.apache.camel:camel-mail