Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01NmdqLTkyN3AtbWZwaM4AAiB_
Jenkins Aqua Security Serverless Scanner Plugin showed plain text password in job configuration form fields
Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.
Permalink: https://github.com/advisories/GHSA-56gj-927p-mfphJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NmdqLTkyN3AtbWZwaM4AAiB_
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 2 years ago
Updated: 9 months ago
CVSS Score: 3.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Percentage: 0.00084
EPSS Percentile: 0.37503
Identifiers: GHSA-56gj-927p-mfph, CVE-2019-10397
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10397
- https://jenkins.io/security/advisory/2019-09-12/#SECURTY-1509
- http://www.openwall.com/lists/oss-security/2019/09/12/2
- https://github.com/advisories/GHSA-56gj-927p-mfph
Affected Packages
maven:org.jenkins-ci.plugins:aqua-serverless
Affected Version Ranges: <= 1.0.4Fixed in: 1.0.5