Severity
7.5HIGH
EPSS
0.8%
top 26.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 12

Description

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Mavenorg.csanchez.jenkins.plugins:kubernetes< 3910.ve59cec5e33ea
NVDjenkins/kubernetes3909.v1f2c633e8590

🔴Vulnerability Details

3
GHSA
Jenkins Kubernetes Plugin does not properly mask credentials2023-04-12
OSV
Jenkins Kubernetes Plugin does not properly mask credentials2023-04-12
CVEList
CVE-2023-30513: Jenkins Kubernetes Plugin 39092023-04-12

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2023-04-122023-04-12
Red Hat
jenkins: Improper masking of credentials in multiple plugins2023-04-12
CVE-2023-30513 (HIGH CVSS 7.5) | Jenkins Kubernetes Plugin 3909.v1f2 | cvebase.io