CVE-2023-43494

MEDIUM

Jenkins 2.50-2.423 LTS 2.60.1-2.414.1 - Info Disclosure

Title source: llm

Description

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

Exploits (1)

nomisec SCANNER
by mqxmm · poc
https://github.com/mqxmm/CVE-2023-43494

Scores

CVSS v3 4.3
EPSS 0.5327
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (3)
jenkins/jenkins 2.50 - 2.424
jenkins/jenkins 2.60.1 - 2.414.2
org.jenkins-ci.main/jenkins-core 2.50 - 2.414.2Maven
Published Sep 20, 2023
Tracked Since Feb 18, 2026