CVE-2023-30523

Severity
4.3MEDIUM
EPSS
0.3%
top 42.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12

Description

Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

🔴Vulnerability Details

3
OSV
Jenkins Report Portal Plugin allows users with Item/Extended Read permission to view tokens on Jenkins controller2023-04-12
CVEList
CVE-2023-30523: Jenkins Report Portal Plugin 02023-04-12
GHSA
Jenkins Report Portal Plugin allows users with Item/Extended Read permission to view tokens on Jenkins controller2023-04-12

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-04-122023-04-12
CVE-2023-30523 (MEDIUM CVSS 4.3) | Jenkins Report Portal Plugin 0.5 an | cvebase.io