Description
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2065
Related Vulnerabilities
CVE-2018-16330 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2021-23438 Vulnerability in npm package mpath
CVE-2021-21633 Vulnerability in maven package org.jenkins-ci.plugins:dependency-track
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika
CVE-2019-16542 Vulnerability in maven package org.jenkins-ci.plugins:anchore-container-scanner