CVE-2023-25721
Last modified
CVE-2023-25721 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting debug is enabled and when a scan is configured for remote agent jobs, allows users (with access to view the job log) to discover proxy credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Veracode | Veracode | < 23.3.19.0 |
References
- https://veracode.comVendor Advisory
- https://veracode.comVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-25721?
How severe is CVE-2023-25721?
How do I fix CVE-2023-25721?
Are you affected by CVE-2023-25721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
