cbcvebase.
CVE-2023-41934
published 2023-09-06

CVE-2023-41934: Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials…

PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.54%
42.0th percentile
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsassembla_auth_plugin
jenkinsaws_codecommit_trigger_plugin
jenkinsbitbucket_push_and_pull_request_plugin
jenkinsconfig_file_provider_plugin
jenkinsdisabled_permissions_can_be_granted_by_ssh2_easy_plugin
jenkinsdisabled_permissions_granted_by_assembla_auth_plugin
jenkinsfrugal_testing_plugin
jenkinsgoogle_login_plugin
jenkinsivy_plugin
jenkinsjob_configuration_history_plugin
jenkinsnon-constant_time_token_comparison_in_google_login_plugin
jenkinspipeline_maven_integration<= 1330.v18e473854496
jenkinspipeline_maven_integration_plugin
jenkinsqualys_container_scanning_connector_plugin
jenkinsssh2_easy_plugin
jenkinstap_plugin
jenkins_projectjenkins_pipeline_maven_integration_plugin<= 1330.v18e473854496
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.