Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-1329 Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.
Github GHSA Github GHSA GHSA-j55j-28wc-v338 Jenkins Report Portal Plugin configuration form does not mask tokens
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1270
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2025-02-07T16:57:04.169Z

Reserved: 2023-04-12T08:40:40.604Z

Link: CVE-2023-30524

cve-icon Vulnrichment

Updated: 2024-08-02T14:28:51.276Z

cve-icon NVD

Status : Modified

Published: 2023-04-12T18:15:10.687

Modified: 2025-02-07T17:15:28.253

Link: CVE-2023-30524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.