Description
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/09/21/5
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2243
Related Vulnerabilities
CVE-2020-7598 Vulnerability in maven package org.webjars.npm:minimist
CVE-2023-5217 Vulnerability in npm package electron
CVE-2019-16775 Vulnerability in maven package org.webjars:npm
CVE-2020-7755 Vulnerability in npm package dat.gui
CVE-2020-6428 Vulnerability in maven package org.webjars.npm:electron