Description
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/07/02/7
https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1627
Related Vulnerabilities
CVE-2021-45456 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2022-25301 Vulnerability in npm package jsgui-lang-essentials
CVE-2021-34080 Vulnerability in npm package ssl-utils
CVE-2020-19698 Vulnerability in maven package org.webjars.bower:editor.md