Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-40339

Опубликовано: 16 авг. 2023
Источник: redhat
CVSS3: 7.5

Описание

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.

A flaw was found in the Config File Provider Jenkins Plugin. Affected versions of this plugin do not mask (replace with asterisks) credentials specified in configuration files when they're written to the build log.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsOut of support scope
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2024:077812.02.2024
OCP-Tools-4.14-RHEL-8jenkins-2-pluginsFixedRHSA-2024:077712.02.2024

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2232423jenkins-plugins: config-file-provider: Improper masking of credentials in Config File Provider Plugin

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.

CVSS3: 4.3
github
больше 2 лет назад

Jenkins Config File Provider Plugin improper credential masking vulnerability

7.5 High

CVSS3