{"id":"GHSA-gqxr-hvrw-6hfh","summary":"Jenkins NS-ND Integration Performance Publisher Plugin displays credentials without masking","details":"Jenkins NS-ND Integration Performance Publisher Plugin stores credentials in job config.xml files on the Jenkins controller as part of its configuration.\n\nWhile these credentials are stored encrypted on disk, in NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier, the job configuration form does not mask these credentials, increasing the potential for attackers to observe and capture them.\n\nNS-ND Integration Performance Publisher Plugin 4.11.0.48 masks credentials displayed on the configuration form.","aliases":["CVE-2023-33000"],"modified":"2024-02-16T08:24:59.535326Z","published":"2023-05-16T18:30:16Z","database_specific":{"cwe_ids":["CWE-522"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-05-17T03:37:48Z","nvd_published_at":"2023-05-16T17:15:12Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33000"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-2962"}],"affected":[{"package":{"name":"io.jenkins.plugins:cavisson-ns-nd-integration","ecosystem":"Maven","purl":"pkg:maven/io.jenkins.plugins/cavisson-ns-nd-integration"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.11.0.48"}]}],"versions":["4.6.0.23","4.6.0.24","4.6.1.40","4.6.1.65","4.6.1.65.1","4.6.1.65.2","4.6.1.66","4.6.1.68","4.6.1.69","4.6.1.70","4.6.1.76","4.6.1.78","4.6.1.79","4.6.1.80","4.6.1.82","4.6.1.83","4.6.1.85","4.6.1.93","4.8.0.129","4.8.0.130","4.8.0.134","4.8.0.142","4.8.0.143","4.8.0.146","4.8.0.147","4.8.0.148","4.8.0.149","4.8.0.77"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-gqxr-hvrw-6hfh/GHSA-gqxr-hvrw-6hfh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}