Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
{ "cpes": [ "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:jenkins:*:*" ], "severity": "High" }