ZeroHour

CVE-2023-40340

CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.

Vendors
jenkins
Products
nodejs
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.