Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000057

Опубликовано: 05 фев. 2018
Источник: redhat
CVSS3: 5.3

Описание

Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3jenkins-plugin-credentials-bindingWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-117
https://bugzilla.redhat.com/show_bug.cgi?id=1542718jenkins-plugin-credentials-binding: improper masking of the secret provided to the build in rare circumstances

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 8 лет назад

Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.

CVSS3: 4.3
github
больше 3 лет назад

Jenkins Credentials Binding Plugin has Insufficiently Protected Credentials

5.3 Medium

CVSS3