Description
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1016
Related Vulnerabilities
CVE-2013-6407 Vulnerability in maven package org.apache.solr:solr-core
CVE-2021-45105 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2022-34815 Vulnerability in maven package org.jenkins-ci.plugins:rrod
CVE-2016-10726 Vulnerability in maven package org.dspace:dspace-xmlui
CVE-2016-0956 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post