Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Maven

Improper masking of credentials Jenkins in Git Plugin

GHSA-jxmw-3gxf-fprh · CVE-2022-38663

Published · Modified

Description

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (gitUsernamePassword) credentials binding.

Ready to move

Start Securing

Free, no credit card | First findings in minutes