CVE-2023-41934

CVSS v3.1 5.3 (Medium)
53% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 1
Advisories 2

Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-09-06 13:15:10
(12 months ago)
Updated Date
2023-09-12 13:24:46
(12 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Pipeline Maven Integration for Jenkins 1330.v18e473854496 and prior versions cpe:2.3:a:jenkins:pipeline_maven_integration::*:*:*:*:jenkins <= 1330.v18e473854496
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...