Non-encrypted confidential information In org.jenkins-ci.plugins:cloudshare-docker

Description

Jenkins CloudShare Docker-Machine Plugin stores credentials in plain text Jenkins CloudShare Docker-Machine Plugin stores credentials unencrypted in its global configuration file com.cloudshare.jenkins.CloudShareConfiguration.xml on the Jenkins controller. These credentials can be viewed by users with access to the Jenkins controller file system.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version