Description
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-1016
Related Vulnerabilities
CVE-2014-7827 Vulnerability in maven package org.picketlink:picketlink-federation
CVE-2016-0790 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-4863 Vulnerability in npm package electron
CVE-2011-0534 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2023-25571 Vulnerability in npm package @backstage/plugin-catalog-backend