Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jenkins

Published: 2023-09-06T12:08:55.028Z

Updated: 2023-10-24T12:51:43.652Z

Reserved: 2023-09-05T16:39:57.392Z


Link: CVE-2023-41934

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-06T13:15:10.073

Modified: 2023-09-12T13:24:46.640


Link: CVE-2023-41934

JSON object: View

cve-icon Redhat Information

No data.