Description
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.
Remediation
References
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1521
http://www.openwall.com/lists/oss-security/2019/12/17/1
Related Vulnerabilities
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-hikari-dbcp-service
CVE-2012-0393 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-2094 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-jenkins-advisor
CVE-2019-10305 Vulnerability in maven package com.xebialabs.xl-deploy:jenkins-dependendencies
CVE-2018-8035 Vulnerability in maven package org.apache.uima:uima-ducc-web