Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-03-28T00:00:00.000Z
Updated: 2025-02-19T18:33:48.160Z
Reserved: 2023-02-13T00:00:00.000Z
Link: CVE-2023-25721
Updated: 2024-08-02T11:32:11.410Z
Status : Modified
Published: 2023-03-28T20:15:11.093
Modified: 2025-02-19T19:15:13.430
Link: CVE-2023-25721
No data.
ReportizFlow