Description
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1546
http://www.openwall.com/lists/oss-security/2019/10/23/2
Related Vulnerabilities
CVE-2021-43838 Vulnerability in npm package jsx-slack
CVE-2015-7501 Vulnerability in maven package commons-collections:commons-collections
CVE-2023-3481 Vulnerability in npm package critters
CVE-2023-40342 Vulnerability in maven package org.jenkins-ci.plugins:flaky-test-handler
CVE-2012-5885 Vulnerability in maven package tomcat:catalina