Unmasked Credentials in Jenkins Performance Publisher Plugin by Jenkins
CVE-2023-33000
7.5HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 May 2023
What is CVE-2023-33000?
The NS-ND Integration Performance Publisher Plugin for Jenkins fails to mask sensitive credentials displayed on its configuration form. This lack of masking raises the risk of unauthorized access as attackers might observe and capture these credentials during their interaction with the interface. Organizations using this plugin should take immediate action to mitigate the risk and safeguard their credentials to prevent potential breaches.
Affected Version(s)
Jenkins NS-ND Integration Performance Publisher Plugin 0 <= 4.8.0.149