We found results for “”
CVE-2023-41934
Good to know:
Date: September 6, 2023
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Information Exposure Through Log Files
CWE-532Top Fix
Upgrade Version
Upgrade to version org.jenkins-ci.plugins:pipeline-maven:1331.v003efa_fd6e81
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |