Credentials Exposure in Jenkins Pipeline Maven Integration Plugin
CVE-2023-41934
5.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 6 September 2023
What is CVE-2023-41934?
The Jenkins Pipeline Maven Integration Plugin prior to version 1330.v18e473854496 contains a vulnerability that fails to adequately mask usernames of credentials in custom Maven settings during Pipeline builds. When the 'Treat username as secret' option is enabled, this flaw allows the actual usernames to be displayed in the build logs, potentially exposing sensitive information and compromising security. Users are urged to upgrade to a patched version to mitigate this risk.
Affected Version(s)
Jenkins Pipeline Maven Integration Plugin 0 <= 1330.v18e473854496