CVE-2018-12557
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the nolog attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., withitems), the contents of the loop items would be printed in the console. This could lead to accidentally leaking credentials or secrets.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://storyboard.openstack.org/#%21/story/2002177, http://lists.zuul-ci.org/pipermail/zuul-announce/2018-June/000015.html, https://git.zuul-ci.org/cgit/zuul/commit/?id=ffe7278c08e6e36bf8b18f732c764e00ff51551e, https://git.zuul-ci.org/cgit/zuul/commit/?id=ffe7278c08e6e36bf8b18f732c764e00ff51551e, http://lists.zuul-ci.org/pipermail/zuul-announce/2018-June/000015.html
