CVE Vulnerabilities

CVE-2023-41934

Published: Sep 06, 2023 | Modified: Sep 12, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if Treat username as secret is checked.

Affected Software

Name Vendor Start Version End Version
Pipeline_maven_integration Jenkins * 1330.v18e473854496 (including)

References