Description
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1199 | Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it. |
Github GHSA |
GHSA-54cw-rvr3-w6cx | Jenkins Consul KV Builder Plugin stores HashiCorp Consul ACL Token unencrypted |
References
History
Fri, 07 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-07T18:11:07.263Z
Reserved: 2023-04-12T08:40:40.605Z
Link: CVE-2023-30531
Updated: 2024-08-02T14:28:51.969Z
Status : Modified
Published: 2023-04-12T18:15:12.670
Modified: 2025-02-07T19:15:24.343
Link: CVE-2023-30531
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA