7.5
CVE-2023-40339
- EPSS 0.78%
- Veröffentlicht 16.08.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 08:19:15
- Erkennungen
Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Config File Provider SwPlatform jenkins Version <= 952.va_544a_6234b_46
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.528 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
http://www.openwall.com/lists/oss-security/2023/08/16/3
https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3090