Description
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/11/21/1
https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1554
Related Vulnerabilities
CVE-2018-1000118 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-2111 Vulnerability in maven package org.jenkins-ci.plugins:subversion
CVE-2020-2174 Vulnerability in maven package org.jenkins-ci.plugins:awseb-deployment-plugin
CVE-2023-31417 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2020-17530 Vulnerability in maven package org.apache.struts:struts2-core