CVE-2020-2182
published 2020-05-06CVE-2020-2182: Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
PriorityP418medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.88%
55.0th percentile
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | amazon_ec2_plugin | — | — |
| jenkins | copy_artifact_plugin | — | — |
| jenkins | credentials_binding | <= 1.22 | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | cvs_plugin | — | — |
| jenkins | for_more_information_see_the_plugin | — | — |
| jenkins | ids_in_amazon_ec2_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | scm_filter_jervis_plugin | — | — |
| jenkins | when_updating_the_plugin | — | — |
| jenkins_project | jenkins_credentials_binding_plugin | unspecified – 1.22 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper masking of some secrets in Jenkins Credentials Binding Plugin
ghsa·2022-05-24
CVE-2020-2182 [LOW] CWE-522 Improper masking of some secrets in Jenkins Credentials Binding Plugin
Improper masking of some secrets in Jenkins Credentials Binding Plugin
Credentials Binding Plugin allows specifying passwords and other secrets as environment variables, and will hide them from console output in builds. As a side effect of the fix for [SECURITY-698](https://www.jenkins.io/security/advisory/2018-02-05/#credentials-binding), `$` characters in secrets are escaped to `$$`. This will then be expanded to $ again once the secret is passed to (post) build steps.
Credentials Binding Plugin 1.22 and earlier does not mask the escaped form of the secret (containing `$$`). This occurs for example in the \"Execute Maven top-level targets\" build step included in Jenkins.\n\nCredentials Binding Plugin 1.23 now masks secrets both in their original form and with escaped `$` characters, s
OSV
Improper masking of some secrets in Jenkins Credentials Binding Plugin
osv·2022-05-24
CVE-2020-2182 [LOW] Improper masking of some secrets in Jenkins Credentials Binding Plugin
Improper masking of some secrets in Jenkins Credentials Binding Plugin
Credentials Binding Plugin allows specifying passwords and other secrets as environment variables, and will hide them from console output in builds. As a side effect of the fix for [SECURITY-698](https://www.jenkins.io/security/advisory/2018-02-05/#credentials-binding), `$` characters in secrets are escaped to `$$`. This will then be expanded to $ again once the secret is passed to (post) build steps.
Credentials Binding Plugin 1.22 and earlier does not mask the escaped form of the secret (containing `$$`). This occurs for example in the \"Execute Maven top-level targets\" build step included in Jenkins.\n\nCredentials Binding Plugin 1.23 now masks secrets both in their original form and with escaped `$` characters, s
Red Hat
jenkins-credentials-binding-plugin: improper masking of secrets
vendor_redhat·2020-05-06·CVSS 4.3
CVE-2020-2182 [MEDIUM] CWE-222 jenkins-credentials-binding-plugin: improper masking of secrets
jenkins-credentials-binding-plugin: improper masking of secrets
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
Jenkins
Jenkins Security Advisory 2020-05-06
vendor_jenkins·2020-05-06·CVSS 6.5
CVE-2020-2181 [MEDIUM] Jenkins Security Advisory 2020-05-06
Title: Jenkins Security Advisory 2020-05-06
Jenkins Security Advisory 2020-05-06
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Amazon EC2
Plugin
Copy Artifact
Plugin
Credentials Binding
Plugin
CVS
Plugin
SCM Filter Jervis
Plugin
Descriptions
Secrets are not masked by Credentials Binding Plugin in
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
bugzilla·2020-07-29·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
+++ This bug was initially created as a clone of Bug #1861840 +++
+++ This bug was initially created as a clone of Bug #1852331 +++
+++ This bug was initially created as a clone of Bug #1848216 +++
openshift-4 tracking bug for jenkins-2-plugins: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the blocked bugs.
Impact: Moderate
Public Date: 06-May-2020
PM Fix/Wontfix Decision By: 16-Sep-2020
Resolve Bug By: 06-May-2021
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Rememb
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
bugzilla·2020-07-29·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
+++ This bug was initially created as a clone of Bug #1852331 +++
+++ This bug was initially created as a clone of Bug #1848216 +++
openshift-4 tracking bug for jenkins-2-plugins: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the blocked bugs.
Impact: Moderate
Public Date: 06-May-2020
PM Fix/Wontfix Decision By: 16-Sep-2020
Resolve Bug By: 06-May-2021
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this b
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
bugzilla·2020-06-30·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
+++ This bug was initially created as a clone of Bug #1848216 +++
openshift-4 tracking bug for jenkins-2-plugins: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the blocked bugs.
Impact: Moderate
Public Date: 06-May-2020
PM Fix/Wontfix Decision By: 16-Sep-2020
Resolve Bug By: 06-May-2021
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this bug.
Please see the Security Errata Policy for further details: htt
Bugzilla
CVE-2020-2182 jenkins-credentials-binding-plugin: improper masking of secrets
bugzilla·2020-06-16·CVSS 4.3
CVE-2020-2182 [MEDIUM] CVE-2020-2182 jenkins-credentials-binding-plugin: improper masking of secrets
CVE-2020-2182 jenkins-credentials-binding-plugin: improper masking of secrets
A vulnerability was found in Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
Reference:
http://www.openwall.com/lists/oss-security/2020/05/06/3
Discussion:
External References:
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1835
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.4
Via RHSA-2020:3625 https://access.redhat.com/errata/RHSA-2020:3625
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-2182
---
This issue has been addressed
2020-05-06
Published