Insufficiently protected credentials in Jenkins Git plugin

Published: 2022-08-24
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2022-38663
Exploitation vector Network
Public exploit N/A
Vulnerable software
Git plugin
Web applications / Modules and components for CMS

Vendor Jenkins

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Insufficiently protected credentials

EUVDB-ID: #VU66742

Risk: Low


CVE-ID: CVE-2022-38663


Exploit availability:


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected plugin does not properly mask credentials in the build log provided by the Git Username and Password credentials binding. A remote user can gain access to sensitive information on the system.


Install updates from vendor's website.

Vulnerable software versions

Git plugin: 0.1 - 4.11.4

Fixed software versions

CPE2.3 External links

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?