Description
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package ecruve
CVE-2022-37616 Vulnerability in npm package xmldom
CVE-2021-4307 Vulnerability in maven package org.webjars.npm:baobab
CVE-2019-16547 Vulnerability in maven package org.jenkins-ci.plugins:google-compute-engine
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.sonos