Description
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2065
Related Vulnerabilities
CVE-2020-2137 Vulnerability in maven package org.jenkins-ci.plugins:timestamper
CVE-2020-7766 Vulnerability in maven package org.webjars.npm:json-ptr
CVE-2023-34981 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2023-40336 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-folder
CVE-2023-24621 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans