Sensitive Information Exposure in Jenkins Kubernetes Plugin by Jenkins
CVE-2018-1999040
8.8HIGH
What is CVE-2018-1999040?
A vulnerability exists in the Jenkins Kubernetes Plugin that allows unauthorized access to sensitive information. Specifically, the issue arises in the KubernetesCloud.java file where credentials identified by a known credentials ID can be captured by attackers. This flaw was present in versions 1.10.1 and earlier of the Jenkins Kubernetes Plugin, potentially compromising the security of affected Jenkins installations.