CVE-2023-41934

5.3MEDIUM

Key Information

Vendor
Jenkins
Status
Jenkins Pipeline Maven Integration Plugin
Vendor
CVE Published:
6 September 2023

Summary

Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.

Affected Version(s)

Jenkins Pipeline Maven Integration Plugin <= 1330.v18e473854496

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.