Description
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075
Related Vulnerabilities
CVE-2018-15494 Vulnerability in maven package org.webjars.npm:dojox
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-core
CVE-2021-44906 Vulnerability in maven package org.webjars.bowergithub.substack:minimist
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js
CVE-2021-26920 Vulnerability in maven package org.apache.druid:druid-core