Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87063.json"