QID 996970
Date Published: 2024-01-31
QID 996970: Java (Maven) Security Update for org.jenkins-ci.plugins:pipeline-maven (GHSA-9v8g-f9mq-739g)
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9v8g-f9mq-739g for updates and patch information.
Vendor References
- GHSA-9v8g-f9mq-739g -
github.com/advisories/GHSA-9v8g-f9mq-739g
CVEs related to QID 996970
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9v8g-f9mq-739g | org.jenkins-ci.plugins:pipeline-maven |
|