Vulnerability Details CVE-2023-43494
Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.413
EPSS Ranking 97.3%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-43494
-
cpe:2.3:a:jenkins:jenkins:2.100
-
cpe:2.3:a:jenkins:jenkins:2.101
-
cpe:2.3:a:jenkins:jenkins:2.102
-
cpe:2.3:a:jenkins:jenkins:2.103
-
cpe:2.3:a:jenkins:jenkins:2.104
-
cpe:2.3:a:jenkins:jenkins:2.105
-
cpe:2.3:a:jenkins:jenkins:2.106
-
cpe:2.3:a:jenkins:jenkins:2.107
-
cpe:2.3:a:jenkins:jenkins:2.107.1
-
cpe:2.3:a:jenkins:jenkins:2.107.2
-
cpe:2.3:a:jenkins:jenkins:2.107.3
-
cpe:2.3:a:jenkins:jenkins:2.108
-
cpe:2.3:a:jenkins:jenkins:2.109
-
cpe:2.3:a:jenkins:jenkins:2.110
-
cpe:2.3:a:jenkins:jenkins:2.111
-
cpe:2.3:a:jenkins:jenkins:2.112
-
cpe:2.3:a:jenkins:jenkins:2.113
-
cpe:2.3:a:jenkins:jenkins:2.114
-
cpe:2.3:a:jenkins:jenkins:2.115
-
cpe:2.3:a:jenkins:jenkins:2.116
-
cpe:2.3:a:jenkins:jenkins:2.117
-
cpe:2.3:a:jenkins:jenkins:2.118
-
cpe:2.3:a:jenkins:jenkins:2.119
-
cpe:2.3:a:jenkins:jenkins:2.120
-
cpe:2.3:a:jenkins:jenkins:2.121
-
cpe:2.3:a:jenkins:jenkins:2.121.1
-
cpe:2.3:a:jenkins:jenkins:2.121.2
-
cpe:2.3:a:jenkins:jenkins:2.121.3
-
cpe:2.3:a:jenkins:jenkins:2.122
-
cpe:2.3:a:jenkins:jenkins:2.123
-
cpe:2.3:a:jenkins:jenkins:2.124
-
cpe:2.3:a:jenkins:jenkins:2.125
-
cpe:2.3:a:jenkins:jenkins:2.126
-
cpe:2.3:a:jenkins:jenkins:2.127
-
cpe:2.3:a:jenkins:jenkins:2.128
-
cpe:2.3:a:jenkins:jenkins:2.129
-
cpe:2.3:a:jenkins:jenkins:2.130
-
cpe:2.3:a:jenkins:jenkins:2.131
-
cpe:2.3:a:jenkins:jenkins:2.132
-
cpe:2.3:a:jenkins:jenkins:2.133
-
cpe:2.3:a:jenkins:jenkins:2.134
-
cpe:2.3:a:jenkins:jenkins:2.135
-
cpe:2.3:a:jenkins:jenkins:2.136
-
cpe:2.3:a:jenkins:jenkins:2.137
-
cpe:2.3:a:jenkins:jenkins:2.138
-
cpe:2.3:a:jenkins:jenkins:2.138.1
-
cpe:2.3:a:jenkins:jenkins:2.138.2
-
cpe:2.3:a:jenkins:jenkins:2.138.3
-
cpe:2.3:a:jenkins:jenkins:2.138.4
-
cpe:2.3:a:jenkins:jenkins:2.139
-
cpe:2.3:a:jenkins:jenkins:2.140
-
cpe:2.3:a:jenkins:jenkins:2.141
-
cpe:2.3:a:jenkins:jenkins:2.142
-
cpe:2.3:a:jenkins:jenkins:2.143
-
cpe:2.3:a:jenkins:jenkins:2.144
-
cpe:2.3:a:jenkins:jenkins:2.145
-
cpe:2.3:a:jenkins:jenkins:2.146
-
cpe:2.3:a:jenkins:jenkins:2.147
-
cpe:2.3:a:jenkins:jenkins:2.148
-
cpe:2.3:a:jenkins:jenkins:2.149
-
cpe:2.3:a:jenkins:jenkins:2.150
-
cpe:2.3:a:jenkins:jenkins:2.150.1
-
cpe:2.3:a:jenkins:jenkins:2.150.2
-
cpe:2.3:a:jenkins:jenkins:2.150.3
-
cpe:2.3:a:jenkins:jenkins:2.151
-
cpe:2.3:a:jenkins:jenkins:2.152
-
cpe:2.3:a:jenkins:jenkins:2.153
-
cpe:2.3:a:jenkins:jenkins:2.154
-
cpe:2.3:a:jenkins:jenkins:2.155
-
cpe:2.3:a:jenkins:jenkins:2.156
-
cpe:2.3:a:jenkins:jenkins:2.157
-
cpe:2.3:a:jenkins:jenkins:2.158
-
cpe:2.3:a:jenkins:jenkins:2.159
-
cpe:2.3:a:jenkins:jenkins:2.160
-
cpe:2.3:a:jenkins:jenkins:2.161
-
cpe:2.3:a:jenkins:jenkins:2.162
-
cpe:2.3:a:jenkins:jenkins:2.163
-
cpe:2.3:a:jenkins:jenkins:2.164
-
cpe:2.3:a:jenkins:jenkins:2.164.1
-
cpe:2.3:a:jenkins:jenkins:2.164.2
-
cpe:2.3:a:jenkins:jenkins:2.164.3
-
cpe:2.3:a:jenkins:jenkins:2.165
-
cpe:2.3:a:jenkins:jenkins:2.166
-
cpe:2.3:a:jenkins:jenkins:2.167
-
cpe:2.3:a:jenkins:jenkins:2.168
-
cpe:2.3:a:jenkins:jenkins:2.169
-
cpe:2.3:a:jenkins:jenkins:2.170
-
cpe:2.3:a:jenkins:jenkins:2.171
-
cpe:2.3:a:jenkins:jenkins:2.172
-
cpe:2.3:a:jenkins:jenkins:2.173
-
cpe:2.3:a:jenkins:jenkins:2.174
-
cpe:2.3:a:jenkins:jenkins:2.175
-
cpe:2.3:a:jenkins:jenkins:2.176
-
cpe:2.3:a:jenkins:jenkins:2.176.1
-
cpe:2.3:a:jenkins:jenkins:2.176.2
-
cpe:2.3:a:jenkins:jenkins:2.176.3
-
cpe:2.3:a:jenkins:jenkins:2.176.4
-
cpe:2.3:a:jenkins:jenkins:2.187
-
cpe:2.3:a:jenkins:jenkins:2.189
-
cpe:2.3:a:jenkins:jenkins:2.190
-
cpe:2.3:a:jenkins:jenkins:2.190.1
-
cpe:2.3:a:jenkins:jenkins:2.190.2
-
cpe:2.3:a:jenkins:jenkins:2.190.3
-
cpe:2.3:a:jenkins:jenkins:2.191
-
cpe:2.3:a:jenkins:jenkins:2.192
-
cpe:2.3:a:jenkins:jenkins:2.193
-
cpe:2.3:a:jenkins:jenkins:2.194
-
cpe:2.3:a:jenkins:jenkins:2.195
-
cpe:2.3:a:jenkins:jenkins:2.196
-
cpe:2.3:a:jenkins:jenkins:2.197
-
cpe:2.3:a:jenkins:jenkins:2.198
-
cpe:2.3:a:jenkins:jenkins:2.199
-
cpe:2.3:a:jenkins:jenkins:2.204
-
cpe:2.3:a:jenkins:jenkins:2.204.1
-
cpe:2.3:a:jenkins:jenkins:2.204.2
-
cpe:2.3:a:jenkins:jenkins:2.204.3
-
cpe:2.3:a:jenkins:jenkins:2.204.4
-
cpe:2.3:a:jenkins:jenkins:2.204.5
-
cpe:2.3:a:jenkins:jenkins:2.204.6
-
cpe:2.3:a:jenkins:jenkins:2.218
-
cpe:2.3:a:jenkins:jenkins:2.222
-
cpe:2.3:a:jenkins:jenkins:2.222.1
-
cpe:2.3:a:jenkins:jenkins:2.222.3
-
cpe:2.3:a:jenkins:jenkins:2.222.4
-
cpe:2.3:a:jenkins:jenkins:2.227
-
cpe:2.3:a:jenkins:jenkins:2.235
-
cpe:2.3:a:jenkins:jenkins:2.235.1
-
cpe:2.3:a:jenkins:jenkins:2.235.2
-
cpe:2.3:a:jenkins:jenkins:2.235.3
-
cpe:2.3:a:jenkins:jenkins:2.235.4
-
cpe:2.3:a:jenkins:jenkins:2.235.5
-
cpe:2.3:a:jenkins:jenkins:2.244
-
cpe:2.3:a:jenkins:jenkins:2.249
-
cpe:2.3:a:jenkins:jenkins:2.249.1
-
cpe:2.3:a:jenkins:jenkins:2.249.2
-
cpe:2.3:a:jenkins:jenkins:2.249.3
-
cpe:2.3:a:jenkins:jenkins:2.251
-
cpe:2.3:a:jenkins:jenkins:2.263.1
-
cpe:2.3:a:jenkins:jenkins:2.263.2
-
cpe:2.3:a:jenkins:jenkins:2.263.3
-
cpe:2.3:a:jenkins:jenkins:2.263.4
-
cpe:2.3:a:jenkins:jenkins:2.270
-
cpe:2.3:a:jenkins:jenkins:2.274
-
cpe:2.3:a:jenkins:jenkins:2.276
-
cpe:2.3:a:jenkins:jenkins:2.277
-
cpe:2.3:a:jenkins:jenkins:2.277.1
-
cpe:2.3:a:jenkins:jenkins:2.277.2
-
cpe:2.3:a:jenkins:jenkins:2.277.3
-
cpe:2.3:a:jenkins:jenkins:2.277.4
-
cpe:2.3:a:jenkins:jenkins:2.289.1
-
cpe:2.3:a:jenkins:jenkins:2.289.2
-
cpe:2.3:a:jenkins:jenkins:2.289.3
-
cpe:2.3:a:jenkins:jenkins:2.299
-
cpe:2.3:a:jenkins:jenkins:2.300
-
cpe:2.3:a:jenkins:jenkins:2.303
-
cpe:2.3:a:jenkins:jenkins:2.303.1
-
cpe:2.3:a:jenkins:jenkins:2.303.2
-
cpe:2.3:a:jenkins:jenkins:2.303.3
-
cpe:2.3:a:jenkins:jenkins:2.318
-
cpe:2.3:a:jenkins:jenkins:2.319
-
cpe:2.3:a:jenkins:jenkins:2.319.1
-
cpe:2.3:a:jenkins:jenkins:2.319.2
-
cpe:2.3:a:jenkins:jenkins:2.319.3
-
cpe:2.3:a:jenkins:jenkins:2.333
-
cpe:2.3:a:jenkins:jenkins:2.334
-
cpe:2.3:a:jenkins:jenkins:2.375.3
-
cpe:2.3:a:jenkins:jenkins:2.375.4
-
cpe:2.3:a:jenkins:jenkins:2.387.3
-
cpe:2.3:a:jenkins:jenkins:2.393
-
cpe:2.3:a:jenkins:jenkins:2.394
-
cpe:2.3:a:jenkins:jenkins:2.399
-
cpe:2.3:a:jenkins:jenkins:2.400
-
cpe:2.3:a:jenkins:jenkins:2.401.1
-
cpe:2.3:a:jenkins:jenkins:2.401.2
-
cpe:2.3:a:jenkins:jenkins:2.401.3
-
cpe:2.3:a:jenkins:jenkins:2.414.1
-
cpe:2.3:a:jenkins:jenkins:2.423
-
cpe:2.3:a:jenkins:jenkins:2.50
-
cpe:2.3:a:jenkins:jenkins:2.51
-
cpe:2.3:a:jenkins:jenkins:2.52
-
cpe:2.3:a:jenkins:jenkins:2.53
-
cpe:2.3:a:jenkins:jenkins:2.54
-
cpe:2.3:a:jenkins:jenkins:2.55
-
cpe:2.3:a:jenkins:jenkins:2.56
-
cpe:2.3:a:jenkins:jenkins:2.57
-
cpe:2.3:a:jenkins:jenkins:2.58
-
cpe:2.3:a:jenkins:jenkins:2.59
-
cpe:2.3:a:jenkins:jenkins:2.60
-
cpe:2.3:a:jenkins:jenkins:2.60.1
-
cpe:2.3:a:jenkins:jenkins:2.60.2
-
cpe:2.3:a:jenkins:jenkins:2.60.3
-
cpe:2.3:a:jenkins:jenkins:2.61
-
cpe:2.3:a:jenkins:jenkins:2.62
-
cpe:2.3:a:jenkins:jenkins:2.63
-
cpe:2.3:a:jenkins:jenkins:2.64
-
cpe:2.3:a:jenkins:jenkins:2.65
-
cpe:2.3:a:jenkins:jenkins:2.66
-
cpe:2.3:a:jenkins:jenkins:2.67
-
cpe:2.3:a:jenkins:jenkins:2.68
-
cpe:2.3:a:jenkins:jenkins:2.69
-
cpe:2.3:a:jenkins:jenkins:2.70
-
cpe:2.3:a:jenkins:jenkins:2.71
-
cpe:2.3:a:jenkins:jenkins:2.72
-
cpe:2.3:a:jenkins:jenkins:2.73
-
cpe:2.3:a:jenkins:jenkins:2.73.1
-
cpe:2.3:a:jenkins:jenkins:2.73.2
-
cpe:2.3:a:jenkins:jenkins:2.73.3
-
cpe:2.3:a:jenkins:jenkins:2.74
-
cpe:2.3:a:jenkins:jenkins:2.75
-
cpe:2.3:a:jenkins:jenkins:2.76
-
cpe:2.3:a:jenkins:jenkins:2.77
-
cpe:2.3:a:jenkins:jenkins:2.78
-
cpe:2.3:a:jenkins:jenkins:2.79
-
cpe:2.3:a:jenkins:jenkins:2.80
-
cpe:2.3:a:jenkins:jenkins:2.81
-
cpe:2.3:a:jenkins:jenkins:2.82
-
cpe:2.3:a:jenkins:jenkins:2.83
-
cpe:2.3:a:jenkins:jenkins:2.84
-
cpe:2.3:a:jenkins:jenkins:2.85
-
cpe:2.3:a:jenkins:jenkins:2.86
-
cpe:2.3:a:jenkins:jenkins:2.87
-
cpe:2.3:a:jenkins:jenkins:2.88
-
cpe:2.3:a:jenkins:jenkins:2.89
-
cpe:2.3:a:jenkins:jenkins:2.89.1
-
cpe:2.3:a:jenkins:jenkins:2.89.2
-
cpe:2.3:a:jenkins:jenkins:2.89.3
-
cpe:2.3:a:jenkins:jenkins:2.89.4
-
cpe:2.3:a:jenkins:jenkins:2.90
-
cpe:2.3:a:jenkins:jenkins:2.91
-
cpe:2.3:a:jenkins:jenkins:2.92
-
cpe:2.3:a:jenkins:jenkins:2.93
-
cpe:2.3:a:jenkins:jenkins:2.94
-
cpe:2.3:a:jenkins:jenkins:2.95
-
cpe:2.3:a:jenkins:jenkins:2.96
-
cpe:2.3:a:jenkins:jenkins:2.97
-
cpe:2.3:a:jenkins:jenkins:2.98
-
cpe:2.3:a:jenkins:jenkins:2.99