Description
Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3146
Related Vulnerabilities
CVE-2011-3376 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2017-3165 Vulnerability in maven package org.apache.brooklyn:brooklyn-jsgui
CVE-2017-8046 Vulnerability in maven package org.springframework.data:spring-data-rest-webmvc
CVE-2022-43418 Vulnerability in maven package org.jenkins-ci.plugins:katalon
CVE-2022-23619 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web