Description
Jenkins Dingding[??] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-10-01/#SECURITY-1423
http://www.openwall.com/lists/oss-security/2019/10/01/2
https://www.zerodayinitiative.com/advisories/ZDI-19-862/
Related Vulnerabilities
CVE-2017-1000400 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:api-ldap-client-all
CVE-2021-32013 Vulnerability in npm package xlsx
CVE-2022-45380 Vulnerability in maven package org.jenkins-ci.plugins:junit
CVE-2022-24717 Vulnerability in npm package @finastra/ssr-pages