Description
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2064
Related Vulnerabilities
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2019-1003088 Vulnerability in maven package egor-n:fabric-beta-publisher
CVE-2019-1351 Vulnerability in npm package nodegit
CVE-2020-2196 Vulnerability in maven package org.jenkins-ci.plugins:selenium