Medium severity6.5NVD Advisory· Published Aug 23, 2022· Updated Jun 17, 2026
CVE-2022-38663
CVE-2022-38663
Description
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (gitUsernamePassword) credentials binding.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:gitMaven | < 4.11.5 | 4.11.5 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2022/08/23/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-jxmw-3gxf-fprhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-38663ghsaADVISORY
- www.jenkins.io/security/advisory/2022-08-23/nvdVendor AdvisoryWEB
- github.com/jenkinsci/git-plugin/commit/3241db9cc696711c871d4e78b3c3c0daad0740c3ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-08-23Jenkins Security Advisories · Aug 23, 2022