Veracode Scan Jenkins Plugin before 23.3.19.0 is vulnerable to information disclosure of proxy credentials in job logs under specific configurations.
Users are potentially affected if they:
By default, even in this configuration only the job owner or Jenkins admin can view the job log.
{
"cwe_ids": [
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2023-04-05T19:40:36Z",
"nvd_published_at": "2023-03-28T20:15:00Z",
"severity": "MODERATE"
}