Description
Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-3075
Related Vulnerabilities
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http3:http3-qpack
CVE-2023-30517 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-management
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.12
CVE-2023-37963 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator