Description
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1021
Related Vulnerabilities
CVE-2013-2067 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-0105 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2021-21119 Vulnerability in maven package org.webjars.npm:electron
CVE-2013-4221 Vulnerability in maven package org.restlet:org.restlet
CVE-2016-5016 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server