Description
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075
Related Vulnerabilities
CVE-2019-17555 Vulnerability in maven package org.apache.olingo:odata-lib
CVE-2021-20087 Vulnerability in npm package jquery-deparam
CVE-2022-25895 Vulnerability in npm package lite-dev-server
CVE-2015-8855 Vulnerability in maven package org.webjars.bower:semver
CVE-2020-10705 Vulnerability in maven package io.undertow:undertow-core