CVE-2023-30515

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:thycotic_devops_secrets_vault:*:*:*:*:*:jenkins:*:*

History

21 Apr 2023, 16:41

Type Values Removed Values Added
References (MISC) https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075 - (MISC) https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075 - Vendor Advisory
References (MISC) http://www.openwall.com/lists/oss-security/2023/04/13/3 - (MISC) http://www.openwall.com/lists/oss-security/2023/04/13/3 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:jenkins:thycotic_devops_secrets_vault:*:*:*:*:*:jenkins:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-319
First Time Jenkins
Jenkins thycotic Devops Secrets Vault

13 Apr 2023, 21:15

Type Values Removed Values Added
References
  • (MISC) http://www.openwall.com/lists/oss-security/2023/04/13/3 -

12 Apr 2023, 19:08

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-12 18:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-30515

Mitre link : CVE-2023-30515

CVE.ORG link : CVE-2023-30515


JSON object : View

Products Affected

jenkins

  • thycotic_devops_secrets_vault
CWE
CWE-319

Cleartext Transmission of Sensitive Information