Description
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992
http://www.openwall.com/lists/oss-security/2023/04/13/3
Related Vulnerabilities
CVE-2016-1202 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-46650 Vulnerability in maven package com.coravy.hudson.plugins.github:github
CVE-2022-23974 Vulnerability in maven package org.apache.pinot:pinot
CVE-2017-5645 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2016-0710 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed-security