CVE-2023-30513

HIGH

Jenkins Kubernetes Plugin < 3909.v1f2c633e8590 - Cleartext Transmission of Sensitive Information in Build Log

Title source: llm
STIX 2.1

Description

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/04/13/3

Scores

CVSS v3 7.5
EPSS 0.0148
EPSS Percentile 81.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (2)
jenkins/kubernetes < 3909.v1f2c633e8590
org.csanchez.jenkins.plugins/kubernetes 0 - 3910.ve59cec5e33eaMaven
Published Apr 12, 2023
Tracked Since Feb 18, 2026