Description
An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1009
Related Vulnerabilities
CVE-2017-12174 Vulnerability in maven package org.apache.activemq:artemis-core-client
CVE-2023-37950 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2015-5204 Vulnerability in npm package cordova-plugin-file-transfer
CVE-2021-36151 Vulnerability in maven package org.apache.gobblin:gobblin-core
CVE-2019-0205 Vulnerability in maven package org.apache.thrift:libthrift