High severity7.5NVD Advisory· Published May 16, 2023· Updated Jun 17, 2026
CVE-2023-33001
CVE-2023-33001
Description
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.datapipe.jenkins.plugins:hashicorp-vault-pluginMaven | <= 360.v0a | — |
Affected products
3- cpe:2.3:a:jenkins:hashicorp_vault:*:*:*:*:*:wordpress:*:*Range: <=360.v0a_1c04cf807d
- Range: 0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-v3fv-v9m6-26g3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33001ghsaADVISORY
- www.jenkins.io/security/advisory/2023-05-16/nvdVendor AdvisoryWEB
News mentions
1- Jenkins Security Advisory 2023-05-16Jenkins Security Advisories · May 16, 2023