First published: Tue May 16 2023(Updated: )
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Performance Publisher | <=4.8.0.149 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33000 is rated as a high-severity vulnerability due to the exposure of sensitive credentials.
To fix CVE-2023-33000, upgrade the Jenkins NS-ND Integration Performance Publisher Plugin to version 4.8.0.150 or later.
CVE-2023-33000 is a credential exposure vulnerability that affects Jenkins.
CVE-2023-33000 affects users of the Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.149 and earlier.
The impact of CVE-2023-33000 is the potential for unauthorized observers to capture exposed credentials, leading to security breaches.