Description
Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.
Remediation
References
https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-1877
Related Vulnerabilities
CVE-2023-28427 Vulnerability in npm package matrix-js-sdk
CVE-2023-31101 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2021-36774 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2022-34176 Vulnerability in maven package org.jenkins-ci.plugins:junit
CVE-2023-47112 Vulnerability in maven package org.rundeck:rundeck