Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.
These passwords can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
As of publication of this advisory, there is no fix.
{
"github_reviewed_at": "2025-04-02T22:46:28Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-312"
],
"github_reviewed": true,
"nvd_published_at": "2025-04-02T15:16:00Z"
}