Credential Exposure in Jenkins Gitea Plugin Exposing Personal Access Tokens
CVE-2022-46685
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 12 December 2022
What is CVE-2022-46685?
The Jenkins Gitea Plugin prior to version 1.4.4 presents a security concern due to its failure to mask personal access tokens. This oversight could lead to sensitive information being logged during build processes, giving unauthorized access to personal access tokens through build log exposure. Organizations using this plugin should consider updating to the latest version to mitigate potential risks.
Affected Version(s)
Jenkins Gitea Plugin <= 1.4.4