Weak credential policy In com.datapipe.jenkins.plugins:hashicorp-vault-plugin
Description
Improper credentials masking in Jenkins HashiCorp Vault Plugin Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.8.0 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.