Vulnerability Details CVE-2022-43426
Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.1%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-43426
-
cpe:2.3:a:jenkins:s3_explorer:-
-
cpe:2.3:a:jenkins:s3_explorer:1.0.7
-
cpe:2.3:a:jenkins:s3_explorer:1.0.8