Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1374 | Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it. |
Github GHSA |
GHSA-q9hm-hr89-hgm7 | Jenkins WSO2 Oauth Plugin does not mask the WSO2 Oauth client secret on the global configuration form |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-07T18:21:03.216Z
Reserved: 2023-04-12T08:40:40.605Z
Link: CVE-2023-30528
Updated: 2024-08-02T14:28:51.360Z
Status : Modified
Published: 2023-04-12T18:15:11.887
Modified: 2025-02-07T19:15:23.823
Link: CVE-2023-30528
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA