VYPR
Low severityNVD Advisory· Published May 16, 2023· Updated Jan 23, 2025

CVE-2023-33000

CVE-2023-33000

Description

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier exposes credentials in plaintext on the configuration form, enabling attackers with view access to capture them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier exposes credentials in plaintext on the configuration form, enabling attackers with view access to capture them.

CVE-2023-33000 affects the Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.149 and earlier. The plugin fails to mask credentials when displaying them on the configuration form, meaning that sensitive values such as passwords or API tokens are shown in plaintext rather than being obfuscated [1][2].

To exploit this vulnerability, an attacker must have the ability to view the plugin's configuration form. This typically requires at least read access to the Jenkins job or system configuration where the plugin is used. The lack of credential masking increases the risk of credential exposure through shoulder surfing, screen captures, or logging of configuration pages.

The impact is the potential disclosure of credentials used by the plugin to integrate with NS-ND systems. An attacker who obtains these credentials could use them to access external systems or perform actions with the privileges associated with the compromised account.

The Jenkins security advisory recommends updating to a version that properly masks credentials. Users should upgrade to the latest available version of the NS-ND Integration Performance Publisher Plugin to mitigate this vulnerability [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.jenkins.plugins:cavisson-ns-nd-integrationMaven
< 4.11.0.484.11.0.48

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

1