org.jenkins-ci.plugins:mask-passwords
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:mask-passwordspage 1 of 1
- CVE-2019-10370MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.13.02019-08-07
vulnerable: 2.10 ... 2.9 (11 versions)
Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.
- CVE-2022-29043MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.12022-04-12
vulnerable: 2.10 ... 3.0 (13 versions)
Jenkins Mask Passwords Plugin 3.0 and earlier does not escape the name and description of Non-Stored Password parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacker…
Check whether org.jenkins-ci.plugins:mask-passwords is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:mask-passwords CVEs against the assets you own.
Start Free Scan →