Description
Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Published: 2023-04-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-1311 Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Github GHSA Github GHSA GHSA-gmxm-pr58-v5jc Jenkins Azure Key Vault Plugin does not properly mask credentials
History

Fri, 07 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Jenkins Azure Key Vault
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2025-02-07T19:23:20.193Z

Reserved: 2023-04-12T08:40:40.603Z

Link: CVE-2023-30514

cve-icon Vulnrichment

Updated: 2024-08-02T14:28:51.450Z

cve-icon NVD

Status : Modified

Published: 2023-04-12T18:15:08.700

Modified: 2025-02-07T20:15:33.517

Link: CVE-2023-30514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses