Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2522%20%282%29