CVE-2023-41934
5.3MEDIUM
Key Information
- Vendor
- Jenkins
- Status
- Jenkins Pipeline Maven Integration Plugin
- Vendor
- CVE Published:
- 6 September 2023
Summary
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
Affected Version(s)
Jenkins Pipeline Maven Integration Plugin <= 1330.v18e473854496
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database