Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure. As of the publication of the advisory, there are no patches and the plugin is unmaintained.
{ "nvd_published_at": "2019-10-01T14:15:00Z", "github_reviewed_at": "2022-12-06T21:07:51Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-319" ] }