Description
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/08/12/4
https://jenkins.io/security/advisory/2020-08-12/#SECURITY-1975
Related Vulnerabilities
CVE-2021-23760 Vulnerability in npm package keyget
CVE-2019-1003029 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2021-23337 Vulnerability in maven package org.webjars.npm:lodash
CVE-2020-24616 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-44262 Vulnerability in maven package org.ff4j:ff4j-core