CVE-2023-50773
MEDIUMJenkins Dingding JSON Pusher Plugin < 2.0 - Cleartext Storage of Sensitive Information
Title source: llmDescription
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://www.jenkins.io/security/advisory/2023-12-13/#SECURITY-3184
Scores
CVSS v3
4.3
EPSS
0.0035
EPSS Percentile
26.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-312
Status
published
Products (2)
com.zintow/dingding-json-pusher
0Maven
jenkins/dingding_json_pusher
< 2.0
Published
Dec 13, 2023
Tracked Since
Feb 18, 2026