{"api_version":"1","generated_at":"2026-07-24T02:25:19+00:00","cve":"CVE-2023-30515","urls":{"html":"https://cve.report/CVE-2023-30515","api":"https://cve.report/api/cve/CVE-2023-30515.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-30515","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-30515"},"summary":{"title":"CVE-2023-30515","description":"Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.","state":"PUBLIC","assigner":"jenkinsci-cert@googlegroups.com","published_at":"2023-04-12 18:15:00","updated_at":"2023-04-21 16:41:00"},"problem_types":["CWE-319"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2023/04/13/3","name":"http://www.openwall.com/lists/oss-security/2023/04/13/3","refsource":"MISC","tags":[],"title":"oss-security - Re: Multiple vulnerabilities in Jenkins plugins","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075","name":"https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075","refsource":"MISC","tags":[],"title":"Jenkins Security Advisory 2023-04-12","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-30515","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-30515","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"30515","vulnerable":"1","versionEndIncluding":"1.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jenkins","cpe5":"thycotic_devops_secrets_vault","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"jenkins","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-30515","ASSIGNER":"jenkinsci-cert@googlegroups.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Jenkins Project","product":{"product_data":[{"product_name":"Jenkins Thycotic DevOps Secrets Vault Plugin","version":{"version_data":[{"version_affected":"<=","version_name":"0","version_value":"1.0.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075","refsource":"MISC","name":"https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075"},{"url":"http://www.openwall.com/lists/oss-security/2023/04/13/3","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2023/04/13/3"}]}},"nvd":{"publishedDate":"2023-04-12 18:15:00","lastModifiedDate":"2023-04-21 16:41:00","problem_types":["CWE-319"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jenkins:thycotic_devops_secrets_vault:*:*:*:*:*:jenkins:*:*","versionEndIncluding":"1.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}