[MAVEN:GHSA-W7FV-7J46-WWRV] Jenkins Amazon EC2 Plugin leaked beginning of private key in system log

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Amazon EC2 Plugin printed a log message that contained the beginning of the private key to the Jenkins system log.

The log message no longer includes the beginning of the private key.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/ec2 <= 1.43
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/ec2 = 1.44
ID
MAVEN:GHSA-W7FV-7J46-WWRV
Severity
moderate
URL
https://github.com/advisories/GHSA-w7fv-7j46-wwrv
Published
2022-05-24T16:51:51
(2 years ago)
Modified
2023-10-26T22:47:36
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/ec2 org.jenkins-ci.plugins ec2 <= 1.43
Fixed pkg:maven/org.jenkins-ci.plugins/ec2 org.jenkins-ci.plugins ec2 = 1.44
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...