Description
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.
Remediation
References
http://www.securityfocus.com/bid/106532
https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1013%20%281%29
Related Vulnerabilities
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-persistence-elasticsearch-core
CVE-2020-5251 Vulnerability in npm package parse-server
CVE-2021-23337 Vulnerability in maven package org.webjars.npm:lodash.template
CVE-2017-5649 Vulnerability in maven package org.apache.geode:geode-pulse
CVE-2022-23944 Vulnerability in maven package org.apache.shenyu:shenyu-common