Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9768-hprv-crj5

Опубликовано: 09 июл. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.

Credentials Binding Plugin 687.689.v1a_f775332fc9 rethrows exceptions that contain credentials, masking those credentials in the error messages.

Пакеты

Наименование

org.jenkins-ci.plugins:credentials-binding

maven
Затронутые версииВерсия исправления

< 687.689.v1a

687.689.v1a

EPSS

Процентиль: 20%
0.00065
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-522
CWE-779

Связанные уязвимости

CVSS3: 7.3
nvd
7 месяцев назад

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.

EPSS

Процентиль: 20%
0.00065
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-522
CWE-779