Description
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
Remediation
References
https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1303
http://www.openwall.com/lists/oss-security/2019/07/31/1
Related Vulnerabilities
CVE-2021-37136 Vulnerability in maven package io.netty:netty-codec
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client
CVE-2020-9482 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-core
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:activemq-fileserver