Credentials Exposure in Jenkins Pipeline Maven Integration Plugin
CVE-2023-41934
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 6 September 2023
What is CVE-2023-41934?
The Jenkins Pipeline Maven Integration Plugin prior to version 1330.v18e473854496 contains a vulnerability that fails to adequately mask usernames of credentials in custom Maven settings during Pipeline builds. When the 'Treat username as secret' option is enabled, this flaw allows the actual usernames to be displayed in the build logs, potentially exposing sensitive information and compromising security. Users are urged to upgrade to a patched version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Pipeline Maven Integration Plugin 0 <= 1330.v18e473854496
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved