Description
Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file and job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1628
http://www.openwall.com/lists/oss-security/2019/10/23/2
Related Vulnerabilities
CVE-2023-1584 Vulnerability in maven package io.quarkus:quarkus-oidc
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty.aggregate:jetty-all
CVE-2022-36092 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector
CVE-2023-29566 Vulnerability in npm package dawnsparks-node-tesseract