Description
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-06-25/#SECURITY-915
Related Vulnerabilities
CVE-2023-50719 Vulnerability in maven package org.xwiki.platform:xwiki-platform-search-solr-api
CVE-2023-49376 Vulnerability in maven package com.jfinal:jfinal
CVE-2015-5167 Vulnerability in maven package org.apache.ranger:ranger
CVE-2023-35155 Vulnerability in maven package org.xwiki.platform:xwiki-platform-sharepage-api
CVE-2022-41232 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher