Description
Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3146
Related Vulnerabilities
CVE-2020-13949 Vulnerability in maven package org.apache.thrift:libthrift
CVE-2018-1229 Vulnerability in maven package org.springframework.batch:spring-batch-admin
CVE-2022-28889 Vulnerability in maven package org.apache.druid:druid
CVE-2023-32980 Vulnerability in maven package org.jenkins-ci.plugins:email-ext