QID 996961

Date Published: 2024-01-31

QID 996961: PHP (Composer) Security Update for org.jenkins-ci.plugins:aqua-serverless (GHSA-56gj-927p-mfph)

Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 3.1 severity.
  • CVSS V2 rated as Low - 2.6 severity.
  • Solution
    Refer to Github security advisory GHSA-56gj-927p-mfph for updates and patch information.
    Vendor References

    CVEs related to QID 996961

    Software Advisories
    Advisory ID Software Component Link
    GHSA-56gj-927p-mfph org.jenkins-ci.plugins:aqua-serverless URL Logo github.com/advisories/GHSA-56gj-927p-mfph