Jenkins NS-ND Integration Performance Publisher Plugin stores credentials in job config.xml files on the Jenkins controller as part of its configuration.
While these credentials are stored encrypted on disk, in NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier, the job configuration form does not mask these credentials, increasing the potential for attackers to observe and capture them.
NS-ND Integration Performance Publisher Plugin 4.11.0.48 masks credentials displayed on the configuration form.
{ "nvd_published_at": "2023-05-16T17:15:12Z", "cwe_ids": [ "CWE-522" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-05-17T03:37:48Z" }