Description
Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/07/31/1
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1458
Related Vulnerabilities
CVE-2020-17532 Vulnerability in maven package org.apache.servicecomb:foundation-config
CVE-2019-5442 Vulnerability in maven package ro.pippo:pippo-jaxb
CVE-2022-28220 Vulnerability in maven package org.apache.james:james-server-protocols-managesieve
CVE-2014-3744 Vulnerability in npm package st
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-api