Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01NmdqLTkyN3AtbWZwaM4AAiB_
Jenkins Aqua Security Serverless Scanner Plugin showed plain text password in job configuration form fields
Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.
Permalink: https://github.com/advisories/GHSA-56gj-927p-mfphJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NmdqLTkyN3AtbWZwaM4AAiB_
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 2 years ago
Updated: about 1 month ago
CVSS Score: 3.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Identifiers: GHSA-56gj-927p-mfph, CVE-2019-10397
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10397
- https://jenkins.io/security/advisory/2019-09-12/#SECURTY-1509
- http://www.openwall.com/lists/oss-security/2019/09/12/2
- https://github.com/advisories/GHSA-56gj-927p-mfph
Affected Packages
maven:org.jenkins-ci.plugins:aqua-serverless
Affected Version Ranges: <= 1.0.4Fixed in: 1.0.5