CVE Vulnerabilities

CVE-2023-40339

Published: Aug 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when theyre written to the build log.

Affected Software

NameVendorStart VersionEnd Version
Config_file_providerJenkins*952.va_544a_6234b_46 (including)
OCP-Tools-4.12-RHEL-8RedHatjenkins-2-plugins-0:4.12.1706515741-1.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-2-plugins-0:4.14.1706516441-1.el8*

References