Description
An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1009
Related Vulnerabilities
CVE-2018-17193 Vulnerability in maven package org.apache.nifi:nifi-web-utils
CVE-2018-1000136 Vulnerability in npm package electron
CVE-2021-21695 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-40341 Vulnerability in maven package io.jenkins.blueocean:blueocean
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle