GHSA-8fm4-r23p-v68v

Suggest an improvement
Source
https://github.com/advisories/GHSA-8fm4-r23p-v68v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-8fm4-r23p-v68v/GHSA-8fm4-r23p-v68v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8fm4-r23p-v68v
Aliases
  • CVE-2024-28154
Published
2024-03-06T18:30:38Z
Modified
2024-12-06T05:29:24.320550Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Jenkins MQ Notifier Plugin exposes sensitive information in build logs
Details

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Database specific
{
    "nvd_published_at": "2024-03-06T17:15:10Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-03-06T19:21:33Z"
}
References

Affected packages

Maven / com.sonymobile.jenkins.plugins.mq:mq-notifier

Package

Name
com.sonymobile.jenkins.plugins.mq:mq-notifier
View open source insights on deps.dev
Purl
pkg:maven/com.sonymobile.jenkins.plugins.mq/mq-notifier

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.1

Affected versions

1.*

1.0
1.1.5
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.2.10
1.3.0
1.3.1
1.4.0