CVE-2023-33000 – io.jenkins.plugins:cavisson-ns-nd-integration
Package
Manager: maven
Name: io.jenkins.plugins:cavisson-ns-nd-integration
Vulnerable Version: >=0 <4.11.0.48
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00176 pctl0.39415
Details
Jenkins NS-ND Integration Performance Publisher Plugin displays credentials without masking Jenkins NS-ND Integration Performance Publisher Plugin stores credentials in job config.xml files on the Jenkins controller as part of its configuration. While these credentials are stored encrypted on disk, in NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier, the job configuration form does not mask these credentials, increasing the potential for attackers to observe and capture them. NS-ND Integration Performance Publisher Plugin 4.11.0.48 masks credentials displayed on the configuration form.
Metadata
Created: 2023-05-16T18:30:16Z
Modified: 2023-05-17T03:37:48Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-gqxr-hvrw-6hfh/GHSA-gqxr-hvrw-6hfh.json
CWE IDs: ["CWE-522"]
Alternative ID: GHSA-gqxr-hvrw-6hfh
Finding: F035
Auto approve: 1