Veracode Scan Jenkins Plugin before 23.3.19.0 is vulnerable to information disclosure of proxy credentials in job logs under specific configurations.
Users are potentially affected if they: - are using Veracode Scan Jenkins Plugin prior to 23.3.19.0 - AND have configured Veracode Scan to run on remote agent jobs - AND have enabled the "Connect using proxy" option - AND have configured the proxy settings with proxy credentials - AND a Jenkins admin has enabled debug in global system settings.
By default, even in this configuration only the job owner or Jenkins admin can view the job log.
{
"github_reviewed_at": "2023-04-05T19:40:36Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2023-03-28T20:15:00Z",
"cwe_ids": [
"CWE-532"
]
}