VulnerabilityModified
CVE-2023-30515
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
HIGH 7.5EPSS 0.40%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- jenkins/thycotic devops secrets vault
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2023/04/13/3Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/04/13/3Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.