CVE-2023-30531
Description
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing exposure to credential capture.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing exposure to credential capture.
Description
Jenkins Consul KV Builder Plugin versions 2.0.13 and earlier do not mask the HashiCorp Consul ACL Token when displayed on the global configuration form. This means the token is shown in plaintext rather than being obscured (e.g., with asterisks), increasing the risk that an attacker who can view the configuration page might observe and capture the credential [1] [3].
Exploitation
An attacker with access to the Jenkins instance’s global configuration form—typically requiring at least Overall/Read permission—can view the Consul ACL Token in clear text. No special authentication beyond Jenkins credentials is needed to exploit this exposure, as the form displays the token directly without masking [1].
Impact
If an attacker captures the Consul ACL Token, they could use it to authenticate to HashiCorp Consul services with the privileges associated with that token. This could lead to unauthorized access to Consul-managed configuration data, service discovery, or health checking, depending on the token’s permissions [1].
Mitigation
The Jenkins Security Advisory 2023-04-12 lists this as an unresolved issue in the Consul KV Builder Plugin; no patched version has been released as of the advisory date. Administrators are advised to restrict access to the global configuration form and consider using Jenkins’ built-in credential binding features to manage sensitive tokens [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:consul-kv-builderMaven | <= 2.0.13 | — |
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-54cw-rvr3-w6cxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-30531ghsaADVISORY
- www.jenkins.io/security/advisory/2023-04-12/ghsavendor-advisoryWEB
- www.openwall.com/lists/oss-security/2023/04/13/3ghsaWEB
News mentions
1- Jenkins Security Advisory 2023-04-12Jenkins Security Advisories · Apr 12, 2023