Description
Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/10/23/2
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1003
Related Vulnerabilities
CVE-2019-1003089 Vulnerability in maven package ren.helloworld:upload-pgyer
CVE-2019-18797 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2019-16728 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2022-25927 Vulnerability in npm package ua-parser-js
CVE-2020-7788 Vulnerability in maven package org.webjars.npm:ini