CVE-2023-50777

MEDIUM4.3EPSS 0.03%

Tokens stored in plain text by PaaSLane Estimate Plugin

Published: 12/13/2023Modified: 5/22/2025

Description

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References (4)