Vulnerability Description
Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some circumstances.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Gradle | 2.8 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/07/26/2Mailing List
- https://www.jenkins.io/security/advisory/2023-07-26/#SECURITY-3208Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/07/26/2Mailing List
- https://www.jenkins.io/security/advisory/2023-07-26/#SECURITY-3208Vendor Advisory
FAQ
What is CVE-2023-39152?
CVE-2023-39152 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some circumstances.
How severe is CVE-2023-39152?
CVE-2023-39152 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-39152?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Gradle.