AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-43494

MEDIUM · CVSS 4.3 EPSS 3.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-09-20 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. It affects Jenkins.

CVE
CVE-2023-43494
Severity
MEDIUM
CVSS
4.3
EPSS
3.39%
Jenkins

Original NVD Description

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

Related CVEs

Other vulnerabilities affecting the same vendor(s)