CVE-2023-50777
MEDIUM4.3EPSS 0.03%Tokens stored in plain text by PaaSLane Estimate Plugin
Published: 12/13/2023Modified: 5/22/2025
Description
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Affected packages (1)
- Maven/com.cloudtp.jenkins:paaslane-estimatefrom 0, <= 1.0.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |