CVE-2023-50773: Infoleak
Published Dec 13, 2023
·Updated
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Affected Software
2 affected components
maven/com.zintow:dingding-json-pusher<=2.0
Jenkins Dingding Json Pusher Jenkins<=2.0
Event History
Dec 13, 2023
CVE Published
05:30 PM
Data Sourced
05:30 PM
Description
Advisory Published
06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-50773?
CVE-2023-50773 has a medium severity rating due to the risk of exposing sensitive access tokens.
2
How do I fix CVE-2023-50773?
To fix CVE-2023-50773, upgrade the Jenkins Dingding JSON Pusher Plugin to version 2.1 or later.
3
What type of software is affected by CVE-2023-50773?
CVE-2023-50773 affects Jenkins Dingding JSON Pusher Plugin versions up to 2.0 and the corresponding Maven package.
4
What vulnerabilities does CVE-2023-50773 introduce?
CVE-2023-50773 increases the risk of attackers capturing access tokens from the job configuration form.
5
Who is impacted by CVE-2023-50773?
Users of Jenkins who have the Dingding JSON Pusher Plugin installed are impacted by CVE-2023-50773.