Description
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/12/13/4
https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3182
Related Vulnerabilities
CVE-2023-33005 Vulnerability in maven package org.jenkins-ci.plugins:wso2id-oauth
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2021-43859 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-10247 Vulnerability in maven package org.eclipse.jetty:jetty-server