Description
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1021
Related Vulnerabilities
CVE-2022-43425 Vulnerability in maven package io.jenkins.plugins:custom-checkbox-parameter
CVE-2016-3086 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2022-39203 Vulnerability in npm package matrix-appservice-irc
CVE-2015-1796 Vulnerability in maven package org.opensaml:opensaml
CVE-2011-2487 Vulnerability in maven package org.apache.cxf:cxf