Description
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
Remediation
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31549)
WordPress Plugin Easy Filter SQL Injection (1.5)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5406)
WordPress Plugin Print, PDF, Email by PrintFriendly Multiple Unspecified Vulnerabilities (3.5.2)
WordPress Plugin Instagram Feed Cross-Site Scripting (1.4.6.2)