GHSA-7ff8-qfwx-8gx5
Dashboard / Vulnerabilities / GHSA-7ff8-qfwx-8gx5
Summary: Improper masking of some secrets in Jenkins Credentials Binding Plugin
Details: Credentials Binding Plugin allows specifying passwords and other secrets as environment variables, and will hide them from console output in builds. As a side effect of the fix for [SECURITY-698](https://www.jenkins.io/security/advisory/2018-02-05/#credentials-binding), `$` characters in secrets are escaped to `$$`. This will then be expanded to $ again once the secret is passed to (post) build steps. Credentials Binding Plugin 1.22 and earlier does not mask the escaped form of the secret (containing `$$`). This occurs for example in the \"Execute Maven top-level targets\" build step included in Jenkins.\n\nCredentials Binding Plugin 1.23 now masks secrets both in their original form and with escaped `$` characters, so they will be masked even if printed before value expansion.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2182, https://github.com/jenkinsci/credentials-binding-plugin/commit/77681e0d184b0ccafa2a27da3b3bdbba95b4fe8f, https://github.com/jenkinsci/credentials-binding-plugin, https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1835, http://www.openwall.com/lists/oss-security/2020/05/06/3
Affected packages
Package
Name: org.jenkins-ci.plugins:credentials-binding
Purl: pkg:maven/org.jenkins-ci.plugins/credentials-binding
Affected ranges
Type: ECOSYSTEM
Events:
