Description
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Remediation
References
https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp
Related Vulnerabilities
CVE-2022-28135 Vulnerability in maven package org.jvnet.hudson.plugins:instant-messaging
CVE-2023-5763 Vulnerability in maven package org.glassfish.main.orb:orb-connector
CVE-2023-46998 Vulnerability in maven package org.webjars.bower:bootbox.js
CVE-2023-50767 Vulnerability in maven package org.sonatype.nexus.ci:nexus-jenkins-plugin
CVE-2023-32994 Vulnerability in maven package io.jenkins.plugins:miniorange-saml-sp