cbcvebase.
CVE-2020-2181
published 2020-05-06

CVE-2020-2181: Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build…

PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.09%
61.4th percentile
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinsamazon_ec2_plugin
jenkinscopy_artifact_plugin
jenkinscredentials_binding<= 1.22
jenkinscredentials_binding_plugin
jenkinscvs_plugin
jenkinsfor_more_information_see_the_plugin
jenkinsids_in_amazon_ec2_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinsscm_filter_jervis_plugin
jenkinswhen_updating_the_plugin
jenkins_projectjenkins_credentials_binding_pluginunspecified – 1.22

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.