Description
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1562
http://www.openwall.com/lists/oss-security/2020/02/12/3
Related Vulnerabilities
CVE-2015-0254 Vulnerability in maven package javax.servlet.jsp.jstl:jstl
CVE-2021-25946 Vulnerability in npm package nconf-toml
CVE-2022-41232 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher
CVE-2021-35065 Vulnerability in maven package org.webjars.npm:glob-parent
CVE-2017-15707 Vulnerability in maven package org.apache.struts:struts2-core