CVE Vulnerabilities

CVE-2023-40339

Published: Aug 16, 2023 | Modified: Aug 22, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when theyre written to the build log.

Affected Software

Name Vendor Start Version End Version
Config_file_provider Jenkins * 952.va_544a_6234b_46 (including)
OCP-Tools-4.12-RHEL-8 RedHat jenkins-2-plugins-0:4.12.1706515741-1.el8 *
OCP-Tools-4.14-RHEL-8 RedHat jenkins-2-plugins-0:4.14.1706516441-1.el8 *

References