Description
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/02/12/3
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1553
Related Vulnerabilities
CVE-2022-23487 Vulnerability in npm package libp2p
CVE-2020-7768 Vulnerability in maven package org.webjars.npm:grpc
CVE-2020-2208 Vulnerability in maven package org.jenkins-ci.plugins:slack-uploader
CVE-2022-25883 Vulnerability in maven package org.webjars.npm:semver
CVE-2018-11804 Vulnerability in maven package org.apache.spark:spark-core_2.10