Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade atomic-openshift-service-idlerUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-deschedulerUpgrade openshift-kuryrUpgrade python-urllib3Upgrade jenkins-2-pluginsUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-openshift-cluster-autoscalerUpgrade golang-github-openshift-oauth-proxyUpgrade openshift-ansibleUpgrade atomic-openshift-metrics-serverUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-dockerregistryUpgrade golang-github-prometheus-prometheusUpgrade openshift-enterprise-autohealUpgrade golang-github-prometheus-alertmanager | Dec 29, 2020 | May 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub