Description
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.
Remediation
References
https://jenkins.io/security/advisory/2018-06-04/#SECURITY-883
Related Vulnerabilities
CVE-2018-8014 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-36480 Vulnerability in maven package com.aerospike:aerospike-client
CVE-2019-1003024 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2017-12196 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-46242 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore