Loading HuntDB...

GHSA-xj4w-r6gr-x5qm

GitHub Security Advisory

Project Inheritance Plugin showed secret environment variables defined in Mask Passwords Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Project Inheritance Plugin 19.08.02 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.

Affected Packages

Maven hudson.plugins:project-inheritance
Affected versions: 0 (fixed in 19.08.02)

Related CVEs

Key Information

GHSA ID
GHSA-xj4w-r6gr-x5qm
Published
May 24, 2022 10:00 PM
Last Modified
January 30, 2024 9:19 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
hudson.plugins:project-inheritance
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 3, 2025 6:09 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.