Description
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/12/17/1
http://www.openwall.com/lists/oss-security/2019/12/17/1
https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1597
Related Vulnerabilities
CVE-2019-15658 Vulnerability in npm package connect-pg-simple
CVE-2022-2048 Vulnerability in maven package org.eclipse.jetty.http2:http2-server
CVE-2020-2244 Vulnerability in maven package org.jenkins-ci.plugins:build-failure-analyzer
CVE-2019-8331 Vulnerability in maven package org.fujion.webjars:bootstrap
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-dao