[MAVEN:GHSA-56GJ-927P-MFPH] Jenkins Aqua Security Serverless Scanner Plugin showed plain text password in job configuration form fields

Severity Low
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/aqua-serverless <= 1.0.4
ID
MAVEN:GHSA-56GJ-927P-MFPH
Severity
low
URL
https://github.com/advisories/GHSA-56gj-927p-mfph
Published
2022-05-24T16:55:59
(2 years ago)
Modified
2024-04-01T23:48:34
(5 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/aqua-serverless org.jenkins-ci.plugins aqua-serverless <= 1.0.4
Fixed pkg:maven/org.jenkins-ci.plugins/aqua-serverless org.jenkins-ci.plugins aqua-serverless = 1.0.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...