Description
Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/31/1
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-713
Related Vulnerabilities
CVE-2019-3894 Vulnerability in maven package org.wildfly:wildfly-ee
CVE-2020-15119 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2023-31065 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2021-41249 Vulnerability in npm package graphql-playground-react
CVE-2022-28157 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest