Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2023/04/13/3 | Mailing List Third Party Advisory | 
| https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992 | Vendor Advisory | 
| http://www.openwall.com/lists/oss-security/2023/04/13/3 | Mailing List Third Party Advisory | 
| https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992 | Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 08:00
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2023/04/13/3 - Mailing List, Third Party Advisory | |
| References | () https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992 - Vendor Advisory | 
20 Apr 2023, 21:58
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://www.jenkins.io/security/advisory/2023-04-12/#SECURITY-2992 - Vendor Advisory | |
| References | (MISC) http://www.openwall.com/lists/oss-security/2023/04/13/3 - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:jenkins:wso2_oauth:*:*:*:*:*:jenkins:*:* | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.5 | 
| CWE | CWE-312 | |
| First Time | Jenkins wso2 Oauth Jenkins | 
13 Apr 2023, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
12 Apr 2023, 19:08
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-04-12 18:15
Updated : 2025-02-07 19:15
NVD link : CVE-2023-30528
Mitre link : CVE-2023-30528
CVE.ORG link : CVE-2023-30528
JSON object : View
Products Affected
                jenkins
- wso2_oauth
CWE
                
                    
                        
                        CWE-312
                        
            Cleartext Storage of Sensitive Information
