Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0977 | Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials. |
Github GHSA |
GHSA-c4jr-vjm4-27hq | Veracode Scan Jenkins Plugin vulnerable to information disclosure |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 19 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-19T18:33:48.160Z
Reserved: 2023-02-13T00:00:00.000Z
Link: CVE-2023-25721
Updated: 2024-08-02T11:32:11.410Z
Status : Modified
Published: 2023-03-28T20:15:11.093
Modified: 2025-02-19T19:15:13.430
Link: CVE-2023-25721
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA