Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-node-problem-detectorUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-openshift-cluster-autoscalerUpgrade golang-github-openshift-oauth-proxyUpgrade jenkins-2-pluginsUpgrade atomic-openshift-service-idlerUpgrade openshift-kuryrUpgrade python-urllib3Upgrade atomic-openshift-deschedulerUpgrade atomic-openshift-dockerregistryUpgrade openshift-enterprise-autohealUpgrade openshift-ansibleUpgrade golang-github-prometheus-alertmanagerUpgrade golang-github-prometheus-prometheusUpgrade atomic-openshift-metrics-serverUpgrade golang-github-prometheus-node_exporter | Dec 29, 2020 | May 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub