Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v9w3-34xq-hrjg | Tokens stored in plain text by PaaSLane Estimate Plugin |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-22T18:09:21.987Z
Reserved: 2023-12-13T13:06:36.478Z
Link: CVE-2023-50777
Updated: 2024-08-02T22:23:43.907Z
Status : Modified
Published: 2023-12-13T18:15:44.377
Modified: 2025-05-22T19:15:37.483
Link: CVE-2023-50777
No data.
OpenCVE Enrichment
No data.
Github GHSA