Description
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1553
http://www.openwall.com/lists/oss-security/2020/02/12/3
Related Vulnerabilities
CVE-2020-6468 Vulnerability in npm package electron
CVE-2017-9787 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-16563 Vulnerability in maven package tech.andrey.jenkins:mission-control-view
CVE-2022-31070 Vulnerability in npm package @finastra/nestjs-proxy
CVE-2012-6662 Vulnerability in maven package org.fujion.webjars:jquery-ui