Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the com.checkmarx.jenkins:checkmarx-ast-scanner package.
com.checkmarx.jenkins:checkmarx-ast-scanner is a plugin that allows the user to scan their source code using Checkmarx AST platform and provide the results as a feedback.
Affected versions of this package are vulnerable to Embedded Malicious Code. A version of the Checkmarx Jenkins AST plugin was published on the Jenkins Plugin Marketplace containing malicious code intended to scrape and exfiltrate secrets from the Jenkins environment. This is associated with a string of compromises of packages in the Checkmarx ecosystem, including plugins for VSCode and Jenkins, as well as KICS Docker image releases and GitHub Actions, in a campaign attributed to TeamPCP.
The project maintainers recommend downgrading the plugin to version 2.0.13-829.vc72453fa_1c16.