Information Disclosure Vulnerability in Jenkins Consul KV Builder Plugin
CVE-2023-30531
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 12 April 2023
What is CVE-2023-30531?
The Jenkins Consul KV Builder Plugin, up to version 2.0.13, contains a vulnerability that fails to adequately mask the HashiCorp Consul ACL Token within the global configuration form. This oversight increases the risk of attackers observing and capturing sensitive token information, potentially compromising the security of systems utilizing this plugin.
Affected Version(s)
Jenkins Consul KV Builder Plugin 0 <= 2.0.13