A security researcher discovered vulnerabilities in more than 100 plugins of the Jenkins open source software development automation server. Most of the issues are password storage in plain text, and cross-site request forgery (CSRF) issues with missing permission checks that could be exploited by attackers steal credentials. Some of the vulnerable Jenkins plugins have been developed by third-party developers to access a wide range of services, including Twitter, AWS, and Azure. Jenkins developers have released security advisories for unpatched vulnerabilities.”]
Source: https://securityaffairs.co/wordpress/84910/hacking/jenkins-plugins-flaws.html