GHSA-pv2g-vm98-vjxf
Dashboard / Vulnerabilities / GHSA-pv2g-vm98-vjxf
Summary: Jenkins Config File Provider Plugin improper credential masking vulnerability
Details: Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they’re written to the build log. Config File Provider Plugin 953.v0432a_802e4d2 masks credentials configured in configuration files if they appear in the build log.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-40339, https://github.com/jenkinsci/config-file-provider-plugin/commit/0432a802e4d2e4eedfe88f7eb8593f85d1bd69d3, https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3090, http://www.openwall.com/lists/oss-security/2023/08/16/3
Affected packages
Package
Name: org.jenkins-ci.plugins:config-file-provider
Purl: pkg:maven/org.jenkins-ci.plugins/config-file-provider
Affected ranges
Type: ECOSYSTEM
Events:
