Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "5.157.1"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:jenkins:team_foundation_server:*:*:*:*:*:jenkins:*:*"
}