Description
Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.
Remediation
References
https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2480
http://www.openwall.com/lists/oss-security/2022/10/19/3
Related Vulnerabilities
CVE-2021-41580 Vulnerability in npm package passport-oauth2
CVE-2020-26870 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elastic-udfs-parent
CVE-2022-36886 Vulnerability in maven package org.jenkins-ci.plugins:external-monitor-job
CVE-2018-12541 Vulnerability in maven package io.vertx:vertx-core