Description
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075
Related Vulnerabilities
CVE-2020-28500 Vulnerability in maven package org.webjars.bower:lodash
CVE-2021-4260 Vulnerability in npm package oils
CVE-2019-10757 Vulnerability in maven package org.webjars.npm:knex
CVE-2019-10372 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth
CVE-2021-43306 Vulnerability in maven package org.webjars:jquery-validation