Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration
[
{
"id": "CVE-2024-3825-815a0c88",
"signature_type": "Line",
"digest": {
"line_hashes": [
"55398296995959694524739076940016225269",
"330122063651214705191012227075049307410",
"234274248360534585929256143492136284329",
"155875056496282783882920043749546181329",
"160382125366326415660717713472404492987",
"219661249263138735056847431935148003211",
"79775321095685078231227326365503335738",
"310284029113760287968405722837323073299",
"168997451948667948511957876415153309929",
"338280397050770264953318513408125363400",
"170460517245298873969196507643624797939",
"42981816246632752805201141701979958847",
"73988353125373319320259432910118747907"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "src/main/java/hudson/plugins/blazemeter/BlazeMeterPerformanceBuilderDescriptor.java"
},
"source": "https://github.com/blazemeter/blazemeter-jenkins-plugin/commit/11ec94f68136a0612ae1b37b5370053132cb2528",
"deprecated": false
}
]