Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
Moderate severity
GitHub Reviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated Dec 28, 2023
Package
Affected versions
<= 2648.va9433432b33c
Patched versions
2656.vf7a_e7b_75a_457
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Reviewed
Jun 20, 2022
Last updated
Dec 28, 2023
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds.
This allows attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Pipeline: Groovy Plugin 2656.vf7a_e7b_75a_457 does not allow builds containing password parameters to be replayed.
References