SB2022082412 - Insufficiently protected credentials in Jenkins Git plugin
Published: August 24, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficiently protected credentials (CVE-ID: CVE-2022-38663)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected plugin does not properly mask credentials in the build log provided by the Git Username and Password credentials binding. A remote user can gain access to sensitive information on the system.
Remediation
Install update from vendor's website.