Description
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Remediation
References
https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp
Related Vulnerabilities
CVE-2020-1957 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2021-21169 Vulnerability in npm package electron
CVE-2022-46685 Vulnerability in maven package org.jenkins-ci.plugins:gitea
CVE-2021-33609 Vulnerability in maven package com.vaadin:vaadin-server
CVE-2023-34189 Vulnerability in maven package org.apache.inlong:manager-service