Description
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Remediation
References
https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp
Related Vulnerabilities
CVE-2022-28150 Vulnerability in maven package com.synopsys.jenkinsci:ownership
CVE-2021-27905 Vulnerability in maven package org.apache.solr:solr-core
CVE-2020-2279 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-util