Authentication Token Exposure in Jenkins PaaSLane Estimate Plugin
CVE-2023-50777
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50777?
The PaaSLane Estimate Plugin for Jenkins versions 1.0.4 and below fails to properly mask authentication tokens within the job configuration form. This oversight can potentially allow unauthorized users to view and capture sensitive PaaSLane authentication tokens, leading to security risks and possible unauthorized access.
Affected Version(s)
Jenkins PaaSLane Estimate Plugin 0 <= 1.0.4