CVE-2018-1000057

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000057
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000057.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000057
Aliases
Published
2018-02-09T23:29:02Z
Modified
2024-09-03T02:01:11.134078Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.

References

Affected packages

Git / github.com/jenkinsci/credentials-binding-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/credentials-binding-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

credentials-binding-1.*

credentials-binding-1.0
credentials-binding-1.0-beta-1
credentials-binding-1.1
credentials-binding-1.10
credentials-binding-1.11
credentials-binding-1.12
credentials-binding-1.13
credentials-binding-1.14
credentials-binding-1.2
credentials-binding-1.3
credentials-binding-1.4
credentials-binding-1.5
credentials-binding-1.6
credentials-binding-1.7
credentials-binding-1.8
credentials-binding-1.9