PT-2018-11249 · Apache · Zuul
Published
2018-06-19
·
Updated
2018-08-23
·
CVE-2018-12557
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zuul versions prior to 3.1.0
Description
An issue was discovered where if nodes become offline during the build, the no log attribute of a task is ignored. This could lead to accidentally leaking credentials or secrets, particularly when the unreachable error occurred in a task used with a loop variable.
Recommendations
For versions prior to 3.1.0, update to version 3.1.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of loop variables with tasks that may contain sensitive information until a patch is available. Restrict access to the console output to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zuul