cbcvebase.
CVE-2020-2181
published 2020-05-06

CVE-2020-2181: Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build…

medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinsamazon_ec2_plugin
jenkinscopy_artifact_plugin
jenkinscredentials_binding<= 1.22
jenkinscredentials_binding_plugin
jenkinscvs_plugin
jenkinsfor_more_information_see_the_plugin
jenkinsids_in_amazon_ec2_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinsscm_filter_jervis_plugin
jenkinswhen_updating_the_plugin
jenkins_projectjenkins_credentials_binding_pluginunspecified – 1.22