Description
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2021-01-13/#SECURITY-2156
Related Vulnerabilities
CVE-2017-4947 Vulnerability in maven package com.vmware.xenon:xenon-common
CVE-2022-31679 Vulnerability in maven package org.springframework.data:spring-data-rest-webmvc
CVE-2017-2604 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-6532 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-1000067 Vulnerability in maven package org.jenkins-ci.main:jenkins-core