Description
Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/09/25/3
https://jenkins.io/security/advisory/2019-09-25/#SECURITY-1508
Related Vulnerabilities
CVE-2022-24740 Vulnerability in npm package @plone/volto
CVE-2022-25645 Vulnerability in npm package dset
CVE-2021-22134 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2019-10296 Vulnerability in maven package com.urbancode.ds.jenkins.plugins:sra-deploy
CVE-2021-31404 Vulnerability in maven package com.vaadin:flow-server