logo

CVE-2019-10391 com.hcl.security:ibm-application-security

Package

Manager: maven
Name: com.hcl.security:ibm-application-security
Vulnerable Version: >=0 <1.2.5

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00081 pctl0.24555

Details

Jenkins IBM AppScan Plugin showed plain text password in job configuration form fields Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure. This plugin has bee deprecated.

Metadata

Created: 2022-05-24T16:55:01Z
Modified: 2024-01-30T21:20:03Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-65rj-cgrp-g65w/GHSA-65rj-cgrp-g65w.json
CWE IDs: ["CWE-319"]
Alternative ID: GHSA-65rj-cgrp-g65w
Finding: F332
Auto approve: 1