Description
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1022
Related Vulnerabilities
CVE-2023-37944 Vulnerability in maven package org.datadog.jenkins.plugins:datadog
CVE-2019-10363 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2019-20174 Vulnerability in maven package org.webjars.bower:auth0-lock
CVE-2022-28732 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2010-1330 Vulnerability in maven package org.jruby:jruby