{"id":"CVE-2023-32982","details":"Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.","aliases":["GHSA-38hw-368m-7jmg"],"modified":"2026-04-10T04:58:07.923107Z","published":"2023-05-16T16:15:10.920Z","references":[{"type":"ADVISORY","url":"https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3017"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jenkinsci/ansible-plugin","events":[{"introduced":"0"},{"last_affected":"8191fd551ebf606556c730a08eb1d74426dc6257"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"204.v8191fd551eb_f"}]}}],"versions":["146.v431a_a_39d472d","148.v6b_13c6de3a_47","174.vfd5323d2b_9d8","204.v8191fd551eb_f","ansible-0.1","ansible-0.2","ansible-0.3","ansible-0.3.1","ansible-0.4","ansible-0.5","ansible-0.6","ansible-0.6.1","ansible-0.6.2","ansible-0.7","ansible-0.8","ansible-1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32982.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}