Description
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/03/25/2
https://jenkins.io/security/advisory/2020-03-25/#SECURITY-1542%20%281%29
Related Vulnerabilities
CVE-2022-26969 Vulnerability in npm package directus
CVE-2019-1010266 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2020-17530 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-31579 Vulnerability in maven package top.tangyh.basic:lamp-util
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14