Description
Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2944
Related Vulnerabilities
CVE-2021-41251 Vulnerability in npm package @sap-cloud-sdk/core
CVE-2021-20323 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2019-10301 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin
CVE-2022-45347 Vulnerability in maven package org.apache.shardingsphere:shardingsphere-proxy
CVE-2018-1000420 Vulnerability in maven package org.jenkins-ci.plugins:mesos