Description
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Remediation
References
https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp
Related Vulnerabilities
CVE-2022-24785 Vulnerability in maven package org.webjars.bower:moment
CVE-2014-9634 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core
CVE-2022-47500 Vulnerability in maven package org.apache.helix:helix-front
CVE-2022-36897 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage