Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS01NmdqLTkyN3AtbWZwaM4AAiB_

Jenkins Aqua Security Serverless Scanner Plugin showed plain text password in job configuration form fields

Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

Permalink: https://github.com/advisories/GHSA-56gj-927p-mfph
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NmdqLTkyN3AtbWZwaM4AAiB_
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 2 years ago
Updated: about 1 month ago


CVSS Score: 3.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Identifiers: GHSA-56gj-927p-mfph, CVE-2019-10397
References: Blast Radius: 1.0

Affected Packages

maven:org.jenkins-ci.plugins:aqua-serverless
Affected Version Ranges: <= 1.0.4
Fixed in: 1.0.5