CVE-2023-30513: High severity jenkins kubernetes ci vulnerability
Published Apr 12, 2023
·Updated
Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Affected Software
1 affected component
Jenkins Kubernetes Jenkins<=3909.v1f2c633e8590
Event History
Apr 12, 2023
CVE Published
05:05 PM
Data Sourced
05:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-30513?
CVE-2023-30513 has been classified with a moderate severity level due to its potential exposure of sensitive credentials.
2
How do I fix CVE-2023-30513?
To fix CVE-2023-30513, upgrade the Jenkins Kubernetes Plugin to version 3910.v1f2c633e8591 or later.
3
What versions of Jenkins Kubernetes Plugin are affected by CVE-2023-30513?
CVE-2023-30513 affects Jenkins Kubernetes Plugin versions up to and including 3909.v1f2c633e8590.
4
What is the impact of CVE-2023-30513 on Jenkins users?
The impact of CVE-2023-30513 is that sensitive credentials may be exposed in build logs, compromising security.
5
Is there a temporary workaround for CVE-2023-30513?
As a temporary workaround for CVE-2023-30513, consider disabling push mode for durable task logging until the plugin is updated.