Description
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Remediation
References
https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp
Related Vulnerabilities
CVE-2019-10345 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2023-24457 Vulnerability in maven package org.jenkins-ci.plugins:keycloak
CVE-2022-31160 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2023-40342 Vulnerability in maven package org.jenkins-ci.plugins:flaky-test-handler
CVE-2023-25768 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials