Description
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1016
Related Vulnerabilities
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-8203 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2015-8315 Vulnerability in maven package org.webjars.npm:ms
CVE-2021-41303 Vulnerability in maven package org.apache.shiro:shiro-core
CVE-2020-2189 Vulnerability in maven package org.jenkins-ci.plugins:scm-filter-jervis