Lucene search

K
githubGitHub Advisory DatabaseGHSA-8FM4-R23P-V68V
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins MQ Notifier Plugin exposes sensitive information in build logs

2024-03-0618:30:38
GitHub Advisory Database
github.com
11
jenkins
notifier
plugin
sensitive information
build logs
debug information

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Affected configurations

Vulners
Node
com.sonymobile.jenkins.plugins.mqmq-notifierRange<1.4.1
VendorProductVersionCPE
com.sonymobile.jenkins.plugins.mqmq-notifier*cpe:2.3:a:com.sonymobile.jenkins.plugins.mq:mq-notifier:*:*:*:*:*:*:*:*

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%