Description
Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/10/19/3
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2846
Related Vulnerabilities
CVE-2020-6467 Vulnerability in npm package electron
CVE-2022-21192 Vulnerability in npm package serve-lite
CVE-2021-28169 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2019-5422 Vulnerability in npm package buttle
CVE-2021-21624 Vulnerability in maven package org.jenkins-ci.plugins:role-strategy