CVE-2020-2181

MEDIUM

Jenkins Credentials Binding Plugin < 1.22 - Insufficiently Protected Credentials in Build Log

Title source: llm
STIX 2.1

Description

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/05/06/3

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 27.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (2)
jenkins/credentials_binding < 1.22
org.jenkins-ci.plugins/credentials-binding 0 - 1.23Maven
Published May 06, 2020
Tracked Since Feb 18, 2026