Description
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
Remediation
References
http://www.openwall.com/lists/oss-security/2020/05/06/3
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1835
Related Vulnerabilities
CVE-2023-39913 Vulnerability in maven package org.apache.uima:uimaj-core
CVE-2018-1999033 Vulnerability in maven package org.jenkins-ci.plugins:anchore-container-scanner
CVE-2017-7688 Vulnerability in maven package org.apache.openmeetings:openmeetings-core
CVE-2021-4264 Vulnerability in npm package dustjs-linkedin
CVE-2021-39147 Vulnerability in maven package com.thoughtworks.xstream:xstream