7.5

CVE-2023-40340

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Nodejs SwPlatform jenkins Version <= 1.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.474
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2023/08/16/3
Third Party Advisory
Mailing List
https://www.jenkins.io/security/advisory/2023-08-16/#SECURITY-3196
Vendor Advisory