Description
Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-01-24/#SECURITY-2091
Related Vulnerabilities
CVE-2022-23622 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-script
CVE-2022-23223 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2020-11022 Vulnerability in maven package org.webjars.npm:jquery
CVE-2023-25768 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials