CVE Vulnerabilities

CVE-2022-25184

Insufficiently Protected Credentials

Published: Feb 15, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read permission to retrieve the default password parameter value from jobs.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Pipeline:_build_stepJenkins*2.15 (including)
Red Hat OpenShift Container Platform 3.11RedHatjenkins-2-plugins-0:3.11.1650371376-1.el7*
Red Hat OpenShift Container Platform 4.10RedHatjenkins-2-plugins-0:4.10.1647505461-1.el8*
Red Hat OpenShift Container Platform 4.6RedHatjenkins-2-plugins-0:4.6.1650364520-1.el8*
Red Hat OpenShift Container Platform 4.7RedHatjenkins-2-plugins-0:4.7.1648800585-1.el8*
Red Hat OpenShift Container Platform 4.8RedHatjenkins-2-plugins-0:4.8.1646993358-1.el8*
Red Hat OpenShift Container Platform 4.9RedHatjenkins-2-plugins-0:4.9.1647580879-1.el8*

Potential Mitigations

References