Description
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
Remediation
References
https://lists.apache.org/thread/z7084r9cs2r26cszkkgjqpb5bhnxqssp
Related Vulnerabilities
CVE-2019-10375 Vulnerability in maven package hudson.plugins.filesystem_scm:filesystem_scm
CVE-2020-2262 Vulnerability in maven package org.jenkins-ci.plugins:android-lint
CVE-2022-45393 Vulnerability in maven package org.jenkins-ci.plugins:delete-log-plugin
CVE-2019-10463 Vulnerability in maven package org.jenkins-ci.plugins:dynatrace-dashboard
CVE-2022-34807 Vulnerability in maven package org.jenkins-ci.plugins:elasticsearch-query