CVE-2023-40339
16.08.2023, 15:15
Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | config_file_provider | 𝑥 ≤ 952.va_544a_6234b_46 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jenkins_project | jenkins_config_file_provider_plugin | 953.v0432a_802e4d2 ≤ 𝑥 < * | ADP |