Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2023/12/13/4 | Mailing List |
https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3182 | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2023/12/13/4 | Mailing List |
https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3182 | Vendor Advisory |
Configurations
History
22 May 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 |
Information
Published : 2023-12-13 18:15
Updated : 2025-05-22 19:15
NVD link : CVE-2023-50777
Mitre link : CVE-2023-50777
CVE.ORG link : CVE-2023-50777
JSON object : View
Products Affected
jenkins
- paaslane_estimate