Description
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/09/21/5
https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2243
Related Vulnerabilities
CVE-2021-21160 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-28657 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2022-23302 Vulnerability in maven package log4j:log4j
CVE-2020-16041 Vulnerability in npm package electron
CVE-2020-7660 Vulnerability in npm package serialize-javascript