Insufficiently protected credentials in Credentials Binding - CVE-2020-2181
Published: May 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information on the system.
The vulnerability exists due to the affected plugin does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps. A remote authenticated attacker can gain unauthorized access to sensitive information on the target system.
Affected software
Red Hat OpenShift Container Platform
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2020-2181
Red Hat OpenShift Container Platform - update to 4.3.40
jenkins-2-plugins (Red Hat package) - update to 4.4.1598545590-1.el7