Description
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2019-10-23/#SECURITY-1621
http://www.openwall.com/lists/oss-security/2019/10/23/2
Related Vulnerabilities
CVE-2021-41079 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2022-31142 Vulnerability in npm package @fastify/bearer-auth
CVE-2012-4386 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-21169 Vulnerability in npm package express-xss-sanitizer
CVE-2022-35912 Vulnerability in maven package org.grails:grails-databinding