Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2023/04/13/3 | Mailing List Third Party Advisory |
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jenkins
Published: 2023-04-12T17:05:16.410Z
Updated: 2023-10-24T12:49:50.620Z
Reserved: 2023-04-12T08:40:40.605Z
Link: CVE-2023-30528
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-12T18:15:11.887
Modified: 2023-04-20T21:58:36.733
Link: CVE-2023-30528
JSON object: View
Redhat Information
No data.
CWE