Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
{
"severity": "High",
"cpes": [
"cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:jenkins:*:*"
]
}