Improper masking of credentials in Jenkins Pipeline Maven Integration Plugin
Moderate severity
GitHub Reviewed
Published
Sep 6, 2023
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Package
Affected versions
<= 1330.v18e473854496
Patched versions
1331.v003efa_fd6e81
Description
Published by the National Vulnerability Database
Sep 6, 2023
Published to the GitHub Advisory Database
Sep 6, 2023
Reviewed
Jan 30, 2024
Last updated
Sep 26, 2024
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
References