CVE-2023-40339

Source
https://cve.org/CVERecord?id=CVE-2023-40339
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-40339.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-40339
Aliases
Downstream
Published
2023-08-16T15:15:11.547Z
Modified
2025-11-15T06:49:13.406312Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Config File Provider Plugin 952.va544a6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.

References

Affected packages

Git / github.com/jenkinsci/config-file-provider-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/config-file-provider-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

2.*
2.8.1
938.*
938.ve2b_8a_591c596
951.*
951.v0461b_87b_721b_
952.*
952.va_544a_6234b_46
config-file-provider-1.*
config-file-provider-1.0
config-file-provider-1.1
config-file-provider-1.2
config-file-provider-1.4
config-file-provider-1.5
config-file-provider-1.6
config-file-provider-1.6.1
config-file-provider-1.9.1
config-file-provider-2.*
config-file-provider-2.0
config-file-provider-2.1
config-file-provider-2.1.1
config-file-provider-2.10.0
config-file-provider-2.10.1
config-file-provider-2.11
config-file-provider-2.12
config-file-provider-2.13
config-file-provider-2.14-beta
config-file-provider-2.14.1-beta
config-file-provider-2.14.2-beta
config-file-provider-2.15
config-file-provider-2.15.1
config-file-provider-2.15.2-beta
config-file-provider-2.15.3
config-file-provider-2.15.3-beta
config-file-provider-2.15.4
config-file-provider-2.15.5
config-file-provider-2.15.6
config-file-provider-2.15.7
config-file-provider-2.16.0
config-file-provider-2.16.1
config-file-provider-2.16.2
config-file-provider-2.16.3
config-file-provider-2.16.4
config-file-provider-2.17
config-file-provider-2.18
config-file-provider-2.2.1
config-file-provider-2.3
config-file-provider-2.4
config-file-provider-2.5
config-file-provider-2.5.1
config-file-provider-2.6
config-file-provider-2.6.1
config-file-provider-2.6.2
config-file-provider-2.7
config-file-provider-2.7.1
config-file-provider-2.7.2
config-file-provider-2.7.3
config-file-provider-2.7.4
config-file-provider-2.7.5
config-file-provider-2.9.1
config-file-provider-2.9.2
config-file-provider-2.9.3
config-file-provider-3.*
config-file-provider-3.0
config-file-provider-3.1
config-file-provider-3.10.0
config-file-provider-3.11
config-file-provider-3.11.0
config-file-provider-3.11.1
config-file-provider-3.2
config-file-provider-3.3
config-file-provider-3.4
config-file-provider-3.4.1
config-file-provider-3.5
config-file-provider-3.6
config-file-provider-3.6.1
config-file-provider-3.6.2
config-file-provider-3.6.3
config-file-provider-3.7.0
config-file-provider-3.8.0
config-file-provider-3.8.1
config-file-provider-3.8.2
config-file-provider-3.9.0
config-provider-model-1.*
config-provider-model-1.0
config-provider-model-1.1
config-provider-model-1.2
config-provider-model-1.3
config-provider-model-1.3.1
config-provider-model-1.3.2
config-provider-model-1.3.3
config-provider-model-1.3.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-40339.json"