Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1276 | Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. |
Github GHSA |
GHSA-f244-f9fc-w6fq | Jenkins Thycotic DevOps Secrets Vault Plugin does not properly mask credentials |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-07T19:16:52.098Z
Reserved: 2023-04-12T08:40:40.603Z
Link: CVE-2023-30515
Updated: 2024-08-02T14:28:51.790Z
Status : Modified
Published: 2023-04-12T18:15:08.853
Modified: 2025-02-07T20:15:33.690
Link: CVE-2023-30515
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA