QID 997460

Date Published: 2024-02-26

QID 997460: Java (Maven) Security Update for org.jenkins-ci.plugins:aqua-microscanner (GHSA-vv4q-2w98-4v8g)

Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Github security advisory GHSA-vv4q-2w98-4v8g for updates and patch information.
    Vendor References

    CVEs related to QID 997460

    Software Advisories
    Advisory ID Software Component Link
    GHSA-vv4q-2w98-4v8g org.jenkins-ci.plugins:aqua-microscanner URL Logo github.com/advisories/GHSA-vv4q-2w98-4v8g