Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jenkins
Published: 2023-04-12T17:05:16.410Z
Updated: 2024-08-02T14:28:51.360Z
Reserved: 2023-04-12T08:40:40.605Z
Link: CVE-2023-30528
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-12T18:15:11.887
Modified: 2024-11-21T08:00:21.450
Link: CVE-2023-30528
Redhat
No data.