Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1jNGpyLXZqbTQtMjdocc4AAyZE

Veracode Scan Jenkins Plugin vulnerable to information disclosure

Veracode Scan Jenkins Plugin before 23.3.19.0 is vulnerable to information disclosure of proxy credentials in job logs under specific configurations.

Users are potentially affected if they:

By default, even in this configuration only the job owner or Jenkins admin can view the job log.

Permalink: https://github.com/advisories/GHSA-c4jr-vjm4-27hq
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jNGpyLXZqbTQtMjdocc4AAyZE
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 year ago
Updated: about 1 year ago


CVSS Score: 4.4
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-c4jr-vjm4-27hq, CVE-2023-25721
References: Blast Radius: 1.0

Affected Packages

maven:com.veracode.jenkins:veracode-scan
Affected Version Ranges: < 23.3.19.0
Fixed in: 23.3.19.0