Description
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1016
Related Vulnerabilities
CVE-2023-30520 Vulnerability in maven package org.jenkins-ci.plugins:quayio-trigger
CVE-2023-34104 Vulnerability in maven package org.webjars.npm:fast-xml-parser
CVE-2018-1999046 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2183 Vulnerability in maven package org.jenkins-ci.plugins:copyartifact
CVE-2020-2098 Vulnerability in maven package org.jenkins-ci.plugins:sounds