Improper masking of credentials Jenkins in Git Plugin
Moderate severity
GitHub Reviewed
Published
Aug 24, 2022
to the GitHub Advisory Database
•
Updated Jan 5, 2024
Description
Published by the National Vulnerability Database
Aug 23, 2022
Published to the GitHub Advisory Database
Aug 24, 2022
Reviewed
Nov 29, 2022
Last updated
Jan 5, 2024
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (
gitUsernamePassword
) credentials binding.References