Description
Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/12/2
https://jenkins.io/security/advisory/2019-09-12/#SECURTY-1509
Related Vulnerabilities
CVE-2022-43423 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2020-15092 Vulnerability in npm package @knight-lab/timelinejs
CVE-2023-31417 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2019-10776 Vulnerability in npm package git-diff-apply
CVE-2019-10422 Vulnerability in maven package org.ukiuni.callotherjenkins:call-remote-job-plugin