Description
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Remediation
References
https://jenkins.io/security/advisory/2020-09-01/#SECURITY-1506
http://www.openwall.com/lists/oss-security/2020/09/01/3
Related Vulnerabilities
CVE-2021-38296 Vulnerability in maven package org.apache.spark:spark-core
CVE-2022-31018 Vulnerability in maven package com.typesafe.play:play_2.12
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-webflux
CVE-2022-34196 Vulnerability in maven package io.jenkins.plugins:rest-list-parameter