SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-40340

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.

HIGH 7.5EPSS 0.63%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Affected
jenkins/nodejs
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.