Description
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1623 | Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. |
Github GHSA |
GHSA-v3fv-v9m6-26g3 | Jenkins HashiCorp Vault Plugin has improper masking of credentials |
References
History
Thu, 23 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-01-23T15:50:41.687Z
Reserved: 2023-05-16T10:55:43.521Z
Link: CVE-2023-33001
Updated: 2024-08-02T15:32:46.514Z
Status : Modified
Published: 2023-05-16T17:15:12.250
Modified: 2025-01-23T16:15:31.230
Link: CVE-2023-33001
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA