Loading HuntDB...

GHSA-8fm4-r23p-v68v

GitHub Security Advisory

Jenkins MQ Notifier Plugin exposes sensitive information in build logs

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Affected Packages

Maven com.sonymobile.jenkins.plugins.mq:mq-notifier
Affected versions: 0 (fixed in 1.4.1)

Related CVEs

Key Information

GHSA ID
GHSA-8fm4-r23p-v68v
Published
March 6, 2024 6:30 PM
Last Modified
January 21, 2025 6:23 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.sonymobile.jenkins.plugins.mq:mq-notifier
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.