Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-02-09T23:00:00

Updated: 2024-08-05T12:33:48.676Z

Reserved: 2018-02-05T00:00:00

Link: CVE-2018-1000057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-02-09T23:29:02.073

Modified: 2019-10-03T00:03:26.223

Link: CVE-2018-1000057

cve-icon Redhat

Severity : Low

Publid Date: 2018-02-05T00:00:00Z

Links: CVE-2018-1000057 - Bugzilla