Loading HuntDB...

GHSA-hr96-qfvm-52r6

GitHub Security Advisory

Maven Integration Plugin did not mask sensitive values in module build logs

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.

Affected Packages

Maven org.jenkins-ci.main:maven-plugin
Affected versions: 0 (fixed in 3.4)

Related CVEs

Key Information

GHSA ID
GHSA-hr96-qfvm-52r6
Published
May 24, 2022 4:51 PM
Last Modified
December 14, 2023 6:21 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.main:maven-plugin
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.