CVE-2023-33000
Description
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier exposes credentials in plaintext on the configuration form, enabling attackers with view access to capture them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier exposes credentials in plaintext on the configuration form, enabling attackers with view access to capture them.
CVE-2023-33000 affects the Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.149 and earlier. The plugin fails to mask credentials when displaying them on the configuration form, meaning that sensitive values such as passwords or API tokens are shown in plaintext rather than being obfuscated [1][2].
To exploit this vulnerability, an attacker must have the ability to view the plugin's configuration form. This typically requires at least read access to the Jenkins job or system configuration where the plugin is used. The lack of credential masking increases the risk of credential exposure through shoulder surfing, screen captures, or logging of configuration pages.
The impact is the potential disclosure of credentials used by the plugin to integrate with NS-ND systems. An attacker who obtains these credentials could use them to access external systems or perform actions with the privileges associated with the compromised account.
The Jenkins security advisory recommends updating to a version that properly masks credentials. Users should upgrade to the latest available version of the NS-ND Integration Performance Publisher Plugin to mitigate this vulnerability [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.jenkins.plugins:cavisson-ns-nd-integrationMaven | < 4.11.0.48 | 4.11.0.48 |
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-gqxr-hvrw-6hfhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33000ghsaADVISORY
- www.jenkins.io/security/advisory/2023-05-16/ghsavendor-advisoryWEB
News mentions
1- Jenkins Security Advisory 2023-05-16Jenkins Security Advisories · May 16, 2023