CVE Vulnerabilities

CVE-2020-2182

Insufficiently Protected Credentials

Published: May 06, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.3 LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a $ character in some circumstances.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Credentials_bindingJenkins*1.22 (including)
Red Hat OpenShift Container Platform 3.11RedHatatomic-enterprise-service-catalog-1:3.11.248-1.git.1.9aad2ef.el7*
Red Hat OpenShift Container Platform 3.11RedHatatomic-openshift-cluster-autoscaler-0:3.11.248-1.git.1.b5530f6.el7*
Red Hat OpenShift Container Platform 3.11RedHatatomic-openshift-descheduler-0:3.11.248-1.git.1.108ef32.el7*
Red Hat OpenShift Container Platform 3.11RedHatatomic-openshift-dockerregistry-0:3.11.248-1.git.1.bb4a1fc.el7*
Red Hat OpenShift Container Platform 3.11RedHatatomic-openshift-metrics-server-0:3.11.248-1.git.1.b53e0e3.el7*
Red Hat OpenShift Container Platform 3.11RedHatatomic-openshift-node-problem-detector-0:3.11.248-1.git.1.628ff22.el7*
Red Hat OpenShift Container Platform 3.11RedHatatomic-openshift-service-idler-0:3.11.248-1.git.1.4c42a90.el7*
Red Hat OpenShift Container Platform 3.11RedHatgolang-github-openshift-oauth-proxy-0:3.11.248-1.git.1.9885abb.el7*
Red Hat OpenShift Container Platform 3.11RedHatgolang-github-prometheus-alertmanager-0:3.11.248-1.git.1.66abd18.el7*
Red Hat OpenShift Container Platform 3.11RedHatgolang-github-prometheus-node_exporter-0:3.11.248-1.git.1.32f87fc.el7*
Red Hat OpenShift Container Platform 3.11RedHatgolang-github-prometheus-prometheus-0:3.11.248-1.git.1.ad54f5b.el7*
Red Hat OpenShift Container Platform 3.11RedHatjenkins-2-plugins-0:3.11.1593081747-1.el7*
Red Hat OpenShift Container Platform 3.11RedHatopenshift-ansible-0:3.11.248-1.git.0.fd212c7.el7*
Red Hat OpenShift Container Platform 3.11RedHatopenshift-enterprise-autoheal-0:3.11.248-1.git.1.0020348.el7*
Red Hat OpenShift Container Platform 3.11RedHatopenshift-enterprise-cluster-capacity-0:3.11.248-1.git.1.37b107c.el7*
Red Hat OpenShift Container Platform 3.11RedHatopenshift-kuryr-0:3.11.248-1.git.1.f90c804.el7*
Red Hat OpenShift Container Platform 3.11RedHatpython-urllib3-0:1.24.3-1.el7*
Red Hat OpenShift Container Platform 4.3RedHatjenkins-2-plugins-0:4.3.1601981312-1.el7*
Red Hat OpenShift Container Platform 4.4RedHatjenkins-2-plugins-0:4.4.1598545590-1.el7*
Red Hat OpenShift Container Platform 4.5RedHatjenkins-2-plugins-0:4.5.1596698303-1.el7*

Potential Mitigations

References