First published: Wed Oct 25 2023(Updated: )
Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:lambdatest-automation | <1.21.0 | 1.21.0 |
Jenkins | <1.21.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Jenkins plugin is CVE-2023-46653.
The affected version of the lambdatest-automation plugin is 1.20.10 and earlier.
The vulnerability logs the LAMBDATEST Credentials access token at the INFO level, which can result in accidental exposure of the token through the default system log.
The severity of this vulnerability is medium with a CVSS score of 6.5.
To fix this vulnerability, update the lambdatest-automation plugin to version 1.21.0 or newer.