cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2022-29043,https://securityvulnerability.io/vulnerability/CVE-2022-29043,Stored Cross-Site Scripting Vulnerability in Jenkins Mask Passwords Plugin,"The Jenkins Mask Passwords Plugin, versions 3.0 and earlier, suffers from a stored cross-site scripting (XSS) vulnerability. This flaw arises because it does not properly escape the name and description of Non-Stored Password parameters when displayed in views. Attackers with Item/Configure permission can exploit this vulnerability, potentially leading to unauthorized actions and data exposure. It is essential for users to review and update their installations to combat this security risk.",Jenkins,Jenkins Mask Passwords Plugin,5.4,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2022-04-12T19:50:39.000Z,0 CVE-2019-10370,https://securityvulnerability.io/vulnerability/CVE-2019-10370,,"Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.",Jenkins,Jenkins Mask Passwords Plugin,6.5,MEDIUM,0.001560000004246831,false,,false,false,false,,,false,false,,2019-08-07T14:20:23.000Z,0