Description
The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default value.
Remediation
References
Related Vulnerabilities
WordPress Plugin Defa Online Image Protector Cross-Site Scripting (3.3)
WordPress Plugin Cherry Multiple Vulnerabilities (1.2.6)
WordPress Plugin Comment Link Remove and Other Comment Tools Cross-Site Request Forgery (2.1.4)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2011-3192)