Description
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.
Remediation
References
https://jenkins.io/security/advisory/2018-06-04/#SECURITY-883
Related Vulnerabilities
CVE-2022-34192 Vulnerability in maven package org.jenkins-ci.plugins:ontrack
CVE-2020-2321 Vulnerability in maven package org.jenkins-ci.plugins:shelve-project-plugin
CVE-2011-3190 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2015-1926 Vulnerability in maven package org.apache.portals.pluto:portletv3annotateddemo
CVE-2023-37957 Vulnerability in maven package io.jenkins.plugins:pipeline-restful-api