CVE-2022-25180
workflow-cps: Password parameters are included from the original build in replayed builds
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Jenkins Pipeline: Groovy Plugin versiones 2648.va9433432b33c y anteriores, incluye parámetros de contraseña de la construcción original en construcciones reproducidas, permitiendo a atacantes con permiso Run/Replay obtener los valores de los parámetros de contraseña pasados a construcciones anteriores de un Pipeline
A flaw was found in Jenkins. The Pipeline: Groovy Plugin includes password parameters from the original build in replayed builds. This flaw allows attackers with run/replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-15 CVE Reserved
- 2022-02-15 CVE Published
- 2023-09-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2443 | 2023-11-30 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-25180 | 2022-05-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2055795 | 2022-05-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jenkins Search vendor "Jenkins" | Pipeline: Groovy Search vendor "Jenkins" for product "Pipeline: Groovy" | <= 2648.va9433432b33c Search vendor "Jenkins" for product "Pipeline: Groovy" and version " <= 2648.va9433432b33c" | jenkins |
Affected
|