VYPR
Moderate severityNVD Advisory· Published Apr 12, 2023· Updated Feb 7, 2025

CVE-2023-30531

CVE-2023-30531

Description

Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing exposure to credential capture.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing exposure to credential capture.

Description

Jenkins Consul KV Builder Plugin versions 2.0.13 and earlier do not mask the HashiCorp Consul ACL Token when displayed on the global configuration form. This means the token is shown in plaintext rather than being obscured (e.g., with asterisks), increasing the risk that an attacker who can view the configuration page might observe and capture the credential [1] [3].

Exploitation

An attacker with access to the Jenkins instance’s global configuration form—typically requiring at least Overall/Read permission—can view the Consul ACL Token in clear text. No special authentication beyond Jenkins credentials is needed to exploit this exposure, as the form displays the token directly without masking [1].

Impact

If an attacker captures the Consul ACL Token, they could use it to authenticate to HashiCorp Consul services with the privileges associated with that token. This could lead to unauthorized access to Consul-managed configuration data, service discovery, or health checking, depending on the token’s permissions [1].

Mitigation

The Jenkins Security Advisory 2023-04-12 lists this as an unresolved issue in the Consul KV Builder Plugin; no patched version has been released as of the advisory date. Administrators are advised to restrict access to the global configuration form and consider using Jenkins’ built-in credential binding features to manage sensitive tokens [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:consul-kv-builderMaven
<= 2.0.13

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1