CVE Published: 12/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Consul KV Builder Plugin Status : PUBLISHED
CVE-2023-30530 Description
Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.