CVE-2019-10391 – com.hcl.security:ibm-application-security
Package
Manager: maven
Name: com.hcl.security:ibm-application-security
Vulnerable Version: >=0 <1.2.5
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00081 pctl0.24555
Details
Jenkins IBM AppScan Plugin showed plain text password in job configuration form fields Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure. This plugin has bee deprecated.
Metadata
Created: 2022-05-24T16:55:01Z
Modified: 2024-01-30T21:20:03Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-65rj-cgrp-g65w/GHSA-65rj-cgrp-g65w.json
CWE IDs: ["CWE-319"]
Alternative ID: GHSA-65rj-cgrp-g65w
Finding: F332
Auto approve: 1