Description
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
Remediation
References
Related Vulnerabilities
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-19355)
Oracle Database Server CVE-2013-5764 Vulnerability (CVE-2013-5764)
MySQL CVE-2021-2300 Vulnerability (CVE-2021-2300)
WordPress Plugin Contact Form 7 Captcha Cross-Site Request Forgery (0.0.8)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-26477)