Credentials Exposure in Jenkins Pipeline Maven Integration Plugin
CVE-2023-41934

5.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
6 September 2023

Summary

The Jenkins Pipeline Maven Integration Plugin prior to version 1330.v18e473854496 contains a vulnerability that fails to adequately mask usernames of credentials in custom Maven settings during Pipeline builds. When the 'Treat username as secret' option is enabled, this flaw allows the actual usernames to be displayed in the build logs, potentially exposing sensitive information and compromising security. Users are urged to upgrade to a patched version to mitigate this risk.

Affected Version(s)

Jenkins Pipeline Maven Integration Plugin 0 <= 1330.v18e473854496

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.