Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-2144 Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.
Github GHSA Github GHSA GHSA-38xm-xhvj-q2qf Jenkins Credentials Binding Plugin has Insufficiently Protected Credentials
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:33:48.676Z

Reserved: 2018-02-05T00:00:00

Link: CVE-2018-1000057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-09T23:29:02.073

Modified: 2024-11-21T03:39:32.780

Link: CVE-2018-1000057

cve-icon Redhat

Severity : Low

Publid Date: 2018-02-05T00:00:00Z

Links: CVE-2018-1000057 - Bugzilla

cve-icon OpenCVE Enrichment

No data.