GHSA-rwh3-5g7v-3c5m
Dashboard / Vulnerabilities / GHSA-rwh3-5g7v-3c5m
Summary: Password written to the build log by Jenkins SQLPlus Script Runner Plugin
Details: Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier prints the `sqlplus` command invocation to the build logs. This log message does not redact a password provided as part of a command line argument. This password can be viewed by users with Item/Read permission. Jenkins SQLPlus Script Runner Plugin 2.0.13 no longer prints the password in the build logs.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2312, https://github.com/jenkinsci/sqlplus-script-runner-plugin, https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2129
Affected packages
Package
Name: org.jenkins-ci.plugins:sqlplus-script-runner
Purl: pkg:maven/org.jenkins-ci.plugins/sqlplus-script-runner
Affected ranges
Type: ECOSYSTEM
Events:
