Lucene search

K
cve[email protected]CVE-2023-40340
HistoryAug 16, 2023 - 3:15 p.m.

CVE-2023-40340

2023-08-1615:15:11
web.nvd.nist.gov
220
cve-2023-40340
jenkins
nodejs
plugin
credential
masking
npm
pipeline
build logs
security

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

37.4%

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.

Affected configurations

NVD
Node
jenkinsnodejsRange1.6.0jenkins
CPENameOperatorVersion
jenkins:nodejsjenkins nodejsle1.6.0

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Jenkins NodeJS Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "1.6.0",
        "status": "affected",
        "version": "0",
        "versionType": "maven"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

37.4%