Description
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1021
Related Vulnerabilities
CVE-2011-4905 Vulnerability in maven package activemq:activemq
CVE-2022-28731 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2022-36090 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2020-16015 Vulnerability in npm package electron
CVE-2019-10184 Vulnerability in maven package io.undertow:undertow-servlet