Description
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/10/08/5
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2054
Related Vulnerabilities
CVE-2018-18628 Vulnerability in maven package ro.pippo:pippo-session
CVE-2019-10778 Vulnerability in npm package devcert-sanscache
CVE-2020-9484 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-16869 Vulnerability in maven package io.netty:netty-codec-http
CVE-2022-42889 Vulnerability in maven package org.apache.commons:commons-text