Description
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
Remediation
References
Related Vulnerabilities
Undertow Insertion of Sensitive Information into Log File Vulnerability (CVE-2019-10212)
Apache Tomcat Other Vulnerability (CVE-2007-1355)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-2050)
PostgreSQL Resource Management Errors Vulnerability (CVE-2007-4772)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2038)