Description
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/04/13/3
https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2944
Related Vulnerabilities
CVE-2021-23396 Vulnerability in npm package lutils
CVE-2020-36049 Vulnerability in npm package socket.io-parser
CVE-2022-41878 Vulnerability in npm package parse-server
CVE-2020-8127 Vulnerability in maven package org.webjars.npm:reveal.js
CVE-2020-13934 Vulnerability in maven package org.apache.tomcat:tomcat-coyote