Description
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
Remediation
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop 'wpabspath' Parameter Remote File Include (2.2.0)
WordPress Plugin Google Maps by BestWebSoft Cross-Site Scripting (1.3.5)
WordPress Plugin Dynamic Widgets 'id' Parameter Cross-Site Scripting (1.5.1)
PostgreSQL Other Vulnerability (CVE-2006-2313)
Oracle Application Server CVE-2008-2589 Vulnerability (CVE-2008-2589)