CVE-2023-39155

Description

Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.08

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-39155 are affected in Jenkins - chef-identity 2.0.3Windows
Vulnerabilities CVE-2023-39155 are affected in Jenkins - chef-identity for Linux 2.0.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234