PT-2023-5741 · Jenkins · Jenkins Nodejs Plugin+1

James Nord

·

Published

2023-08-16

·

Updated

2023-08-22

·

CVE-2023-40340

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins NodeJS Plugin versions 1.6.0 and earlier
Description The issue is related to the improper masking of credentials in the Npm config file in Pipeline build logs. This could allow a remote attacker to gain unauthorized access to protected information. The vulnerability is associated with errors in processing credentials in the Pipeline build log.
Recommendations For Jenkins NodeJS Plugin versions 1.6.0 and earlier, update to version 1.6.1 or later, which properly masks credentials specified in the Npm config file in Pipeline build logs.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2023-06413
CVE-2023-40340
GHSA-36FG-WHR2-G999

Affected Products

Jenkins
Jenkins Nodejs Plugin