GHSA-pv2g-vm98-vjxf
GitHub Security Advisory
Jenkins Config File Provider Plugin improper credential masking vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they’re written to the build log.
Config File Provider Plugin 953.v0432a_802e4d2 masks credentials configured in configuration files if they appear in the build log.
Affected Packages
Maven
org.jenkins-ci.plugins:config-file-provider
Affected versions:
0
(fixed in 953.v0432a)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.