PT-2020-15394 · Jenkins · Jenkins Credentials Binding Plugin+1

Published

2020-05-06

·

Updated

2023-10-25

·

CVE-2020-2181

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Credentials Binding Plugin versions 1.22 and earlier
Description The issue concerns the Jenkins Credentials Binding Plugin, where secrets are not masked in the build log when the build contains no build steps. This affects the security of sensitive information.
Recommendations For Jenkins Credentials Binding Plugin versions 1.22 and earlier, update to version 1.23 or later to ensure secrets are masked in the build log when the build contains no build steps.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-2181
GHSA-43J2-R4V3-M8JP
RHSA-2020:3453
RHSA-2020:3625
RHSA-2020:4265

Affected Products

Jenkins
Jenkins Credentials Binding Plugin