Description
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2055
Related Vulnerabilities
CVE-2019-10089 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2022-38370 Vulnerability in maven package org.apache.iotdb:iotdb-grafana-connector
CVE-2021-21633 Vulnerability in maven package org.jenkins-ci.plugins:dependency-track
CVE-2011-5245 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs
CVE-2020-11998 Vulnerability in maven package org.apache.activemq:activemq-broker