Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
References:- https://nvd.nist.gov/vuln/detail/CVE-2019-10363
- https://jenkins.io/security/advisory/2019-07-31/#SECURITY-1458
- http://www.openwall.com/lists/oss-security/2019/07/31/1
- https://github.com/jenkinsci/configuration-as-code-plugin/commit/7506d50b846460ec9f4506f0e228d2e44f0d5a3e
- https://github.com/advisories/GHSA-r69h-6c4g-63xf