Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade openshift-enterprise-autohealUpgrade golang-github-prometheus-alertmanagerUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-dockerregistryUpgrade atomic-openshift-metrics-serverUpgrade golang-github-prometheus-prometheusUpgrade openshift-ansibleUpgrade openshift-enterprise-cluster-capacityUpgrade jenkins-2-pluginsUpgrade atomic-openshift-deschedulerUpgrade atomic-openshift-cluster-autoscalerUpgrade openshift-kuryrUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-node-problem-detectorUpgrade python-urllib3Upgrade golang-github-openshift-oauth-proxy | Dec 29, 2020 | May 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub