CVE-2023-2633 MEDIUM

CVE-2023-2633: API keys stored and displayed in plain text by Code Dx Plugin

Vendor Jenkins
Product Jenkins Code Dx Plugin
Weakness CWE-256
Published May 16, 2023
Last update January 22, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.

Key dates

02Disclosure timeline

May 16, 2023 CVE published
January 22, 2025 Record updated