Severity
6.5MEDIUM
EPSS
0.1%
top 72.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps2022-05-24
GHSA
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps2022-05-24
CVEList
CVE-2020-2181: Jenkins Credentials Binding Plugin 12020-05-06

📋Vendor Advisories

2
Red Hat
jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps2020-05-06
Jenkins
Jenkins Security Advisory 2020-05-062020-05-06

💬Community

4
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]2020-07-29
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]2020-07-29
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]2020-06-30
Bugzilla
CVE-2020-2181 jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps2020-06-16