Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.
Weakness
Storing a password in plaintext may result in a system compromise.
Potential Mitigations
References