[MAVEN:GHSA-8FM4-R23P-V68V] Jenkins MQ Notifier Plugin exposes sensitive information in build logs

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

ID
MAVEN:GHSA-8FM4-R23P-V68V
Severity
moderate
URL
https://github.com/advisories/GHSA-8fm4-r23p-v68v
Published
2024-03-06T18:30:38
(6 months ago)
Modified
2024-03-06T19:21:35
(6 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.sonymobile.jenkins.plugins.mq/mq-notifier com.sonymobile.jenkins.plugins.mq mq-notifier < 1.4.1
Fixed pkg:maven/com.sonymobile.jenkins.plugins.mq/mq-notifier com.sonymobile.jenkins.plugins.mq mq-notifier = 1.4.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...