Description
In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.
Remediation
References
https://www.jenkins.io/security/advisory/2022-12-07/#SECURITY-2661
Related Vulnerabilities
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto
CVE-2023-26470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-22621 Vulnerability in npm package @strapi/plugin-email
CVE-2020-2150 Vulnerability in maven package org.jenkins-ci.plugins:quality-gates
CVE-2019-10431 Vulnerability in maven package org.jenkins-ci.plugins:script-security