Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
{
"cpes": [
"cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:jenkins:*:*"
],
"severity": "High"
}