#VU51817 Cleartext storage of sensitive information in Jabber (XMPP) notifier and control - CVE-2021-21634
Published: March 31, 2021
Jabber (XMPP) notifier and control
Jenkins
Description
The vulnerability allows a local user to view the password on the target system.
The vulnerability exists due to the affected software stores passwords unencrypted in its global configuration file "hudson.plugins.jabber.im.transport.JabberPublisher.xml" on the Jenkins controller. A local user with access to the Jenkins controller file system can obtain credentials.