Description
Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1508
Related Vulnerabilities
CVE-2019-16869 Vulnerability in maven package io.netty:netty-codec-http
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system
CVE-2022-36046 Vulnerability in npm package next
CVE-2020-12265 Vulnerability in maven package org.webjars:decompress-tar
CVE-2021-34428 Vulnerability in maven package org.eclipse.jetty:jetty-server