CVE-2023-39155
MEDIUMJenkins Chef Identity Plugin <2.0.3 - Info Disclosure
Title source: llmDescription
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
Scores
CVSS v3
5.3
EPSS
0.0008
EPSS Percentile
23.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-668
Status
published
Affected Products (2)
jenkins/chef_identity
< 2.0.3
org.jenkins-ci.plugins/chef-identity
Maven
Timeline
Published
Jul 26, 2023
Tracked Since
Feb 18, 2026