Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2019/08/07/1 | third party advisory mailing list |
https://jenkins.io/security/advisory/2019-08-07/#SECURITY-157 | vendor advisory |