PT-2020-15394 · Jenkins · Jenkins Credentials Binding Plugin+1
Published
2020-05-06
·
Updated
2023-10-25
·
CVE-2020-2181
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Credentials Binding Plugin versions 1.22 and earlier
Description
The issue concerns the Jenkins Credentials Binding Plugin, where secrets are not masked in the build log when the build contains no build steps. This affects the security of sensitive information.
Recommendations
For Jenkins Credentials Binding Plugin versions 1.22 and earlier, update to version 1.23 or later to ensure secrets are masked in the build log when the build contains no build steps.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Credentials Binding Plugin