PT-2018-11249 · Apache · Zuul
Publicado
2018-06-19
·
Atualizado
2018-08-23
·
CVE-2018-12557
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zuul versions prior to 3.1.0
Description
An issue was discovered where if nodes become offline during the build, the no log attribute of a task is ignored. This could lead to accidentally leaking credentials or secrets, particularly when the unreachable error occurred in a task used with a loop variable.
Recommendations
For versions prior to 3.1.0, update to version 3.1.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of loop variables with tasks that may contain sensitive information until a patch is available. Restrict access to the console output to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zuul