CVE-2023-33001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
16/05/2023
Last modified:
23/01/2025

Description

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:hashicorp_vault:*:*:*:*:*:wordpress:*:* 360.v0a_1c04cf807d (including)