A vulnerability was found in Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps. Reference: http://www.openwall.com/lists/oss-security/2020/05/06/3
External References: https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1374
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.4 Via RHSA-2020:3625 https://access.redhat.com/errata/RHSA-2020:3625
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-2181
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.3 Via RHSA-2020:4265 https://access.redhat.com/errata/RHSA-2020:4265