FlawAtlas
Search the atlas
CVE-2023-40339 High

CVE-2023-40339

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.

Exploit probability 0.7%
Published August 16, 2023
Required by Not available
Last source change July 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

54 explicit affected versions

Maven org.jenkins-ci.plugins:config-file-provider

71 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-40339

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.

View original source
Open Source Vulnerabilities GHSA-pv2g-vm98-vjxf

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they’re written to the build log. Config File Provider Plugin 953.v0432a_802e4d2 masks credentials configured in configuration files if they appear in the build log.

View original source

05 / REFERENCES

Further evidence