Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade golang-github-prometheus-node_exporterUpgrade openshift-enterprise-autohealUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshift-dockerregistryUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-cluster-autoscalerUpgrade jenkins-2-pluginsUpgrade openshift-kuryrUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-metrics-serverUpgrade atomic-openshift-deschedulerUpgrade golang-github-prometheus-prometheusUpgrade openshift-ansibleUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-enterprise-service-catalogUpgrade python-urllib3Upgrade openshift-enterprise-cluster-capacity | Dec 29, 2020 | May 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub