CVE-2023-30531

Description

Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.187

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-30530,CVE-2023-30531 are affected in Jenkins - consul-kv-builder 2.0.13Windows
Vulnerabilities CVE-2023-30530,CVE-2023-30531 are affected in Jenkins - consul-kv-builder for Linux 2.0.13Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234