Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Aqua Security/
  3. Aqua Software Supply Chain Security

Aqua Software Supply Chain Security

Supply chainAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 23/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 4 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~46 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Protect every link in the software supply chain.

by Aqua Security · aquasec.com · source ↗

Screenshots

1
Aqua Software Supply Chain Security — screenshotauto

Known CVEs (4)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-53653 ↗MEDIUM 4.32025

    Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Ext…

  • CVE-2019-10428 ↗HIGH 7.52019

    Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-10397 ↗LOW 3.12019

    Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2019-1003069 ↗HIGH 8.82019

    Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Software Supply Chain Security products

see all →
  • Apiiro Deliver · Apiiro
  • Apiiro SSCS · Apiiro
  • BoostSecurity Cloud-speed Compliance · BoostSecurity
  • BoostSecurity Software Supply Chain Protection · BoostSecurity
  • CI/CD Security · Cycode
  • Chainguard Containers · Chainguard
  • Chainguard Libraries · Chainguard
  • Chainguard OS Packages · Chainguard