CVE-2023-33001

Name
CVE-2023-33001
Description
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3077

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:jenkins:hashicorp_vault:*:*:*:*:*:wordpress:*:* jenkins >= None <= 360.v0a_1c04cf807d

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
jenkins 3.18-community 2.387.3-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.19-community 2.440.3-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins 3.20-community 2.440.2-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
jenkins edge-community 2.452.2-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable