CVE-2022-38663

Severity
6.5MEDIUM
EPSS
2.0%
top 16.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateAug 24

Description

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5jenkins_project/jenkins_git_pluginunspecified4.11.4
NVDjenkins/git4.11.4

🔴Vulnerability Details

3
GHSA
Improper masking of credentials Jenkins in Git Plugin2022-08-24
OSV
Improper masking of credentials Jenkins in Git Plugin2022-08-24
CVEList
CVE-2022-38663: Jenkins Git Plugin 42022-08-23

📋Vendor Advisories

2
Red Hat
jenkins-2-plugins/git: Improper masking of credentials in Git Plugin2022-08-23
Jenkins
Jenkins Security Advisory 2022-08-232022-08-23
CVE-2022-38663 (MEDIUM CVSS 6.5) | Jenkins Git Plugin 4.11.4 and earli | cvebase.io