Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "55398296995959694524739076940016225269", "330122063651214705191012227075049307410", "234274248360534585929256143492136284329", "155875056496282783882920043749546181329", "160382125366326415660717713472404492987", "219661249263138735056847431935148003211", "79775321095685078231227326365503335738", "310284029113760287968405722837323073299", "168997451948667948511957876415153309929", "338280397050770264953318513408125363400", "170460517245298873969196507643624797939", "42981816246632752805201141701979958847", "73988353125373319320259432910118747907" ] }, "id": "CVE-2024-3825-815a0c88", "source": "https://github.com/blazemeter/blazemeter-jenkins-plugin/commit/11ec94f68136a0612ae1b37b5370053132cb2528", "signature_version": "v1", "signature_type": "Line", "target": { "file": "src/main/java/hudson/plugins/blazemeter/BlazeMeterPerformanceBuilderDescriptor.java" }, "deprecated": false } ] }