QID 997459

Date Published: 2024-02-26

QID 997459: Java (Maven) Security Update for org.jenkins-ci.plugins:aqua-security-scanner (GHSA-xp44-8vwr-xwmv)

Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Github security advisory GHSA-xp44-8vwr-xwmv for updates and patch information.
    Vendor References

    CVEs related to QID 997459

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xp44-8vwr-xwmv org.jenkins-ci.plugins:aqua-security-scanner URL Logo github.com/advisories/GHSA-xp44-8vwr-xwmv