CVE-2020-2181
published 2020-05-06CVE-2020-2181: Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.09%
61.4th percentile
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | amazon_ec2_plugin | — | — |
| jenkins | copy_artifact_plugin | — | — |
| jenkins | credentials_binding | <= 1.22 | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | cvs_plugin | — | — |
| jenkins | for_more_information_see_the_plugin | — | — |
| jenkins | ids_in_amazon_ec2_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | scm_filter_jervis_plugin | — | — |
| jenkins | when_updating_the_plugin | — | — |
| jenkins_project | jenkins_credentials_binding_plugin | unspecified – 1.22 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
osv·2022-05-24
CVE-2020-2181 [MEDIUM] Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Jenkins Credentials Binding Plugin 1.23 now masks secrets when the build contains no build steps.
GHSA
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
ghsa·2022-05-24
CVE-2020-2181 [MEDIUM] CWE-522 Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
Secrets are not masked by Jenkins Credentials Binding Plugin in builds without build steps
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Jenkins Credentials Binding Plugin 1.23 now masks secrets when the build contains no build steps.
Red Hat
jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps
vendor_redhat·2020-05-06·CVSS 6.5
CVE-2020-2181 [MEDIUM] CWE-200 jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps
jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Jenkins
Jenkins Security Advisory 2020-05-06
vendor_jenkins·2020-05-06·CVSS 6.5
CVE-2020-2181 [MEDIUM] Jenkins Security Advisory 2020-05-06
Title: Jenkins Security Advisory 2020-05-06
Jenkins Security Advisory 2020-05-06
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Amazon EC2
Plugin
Copy Artifact
Plugin
Credentials Binding
Plugin
CVS
Plugin
SCM Filter Jervis
Plugin
Descriptions
Secrets are not masked by Credentials Binding Plugin in
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
bugzilla·2020-07-29·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
+++ This bug was initially created as a clone of Bug #1861840 +++
+++ This bug was initially created as a clone of Bug #1852331 +++
+++ This bug was initially created as a clone of Bug #1848216 +++
openshift-4 tracking bug for jenkins-2-plugins: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the blocked bugs.
Impact: Moderate
Public Date: 06-May-2020
PM Fix/Wontfix Decision By: 16-Sep-2020
Resolve Bug By: 06-May-2021
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Rememb
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
bugzilla·2020-07-29·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
+++ This bug was initially created as a clone of Bug #1852331 +++
+++ This bug was initially created as a clone of Bug #1848216 +++
openshift-4 tracking bug for jenkins-2-plugins: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the blocked bugs.
Impact: Moderate
Public Date: 06-May-2020
PM Fix/Wontfix Decision By: 16-Sep-2020
Resolve Bug By: 06-May-2021
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this b
Bugzilla
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
bugzilla·2020-06-30·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
CVE-2020-2181 CVE-2020-2182 jenkins-2-plugins: jenkins-credentials-binding-plugin: various flaws [openshift-4]
+++ This bug was initially created as a clone of Bug #1848216 +++
openshift-4 tracking bug for jenkins-2-plugins: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes in the blocked bugs.
Impact: Moderate
Public Date: 06-May-2020
PM Fix/Wontfix Decision By: 16-Sep-2020
Resolve Bug By: 06-May-2021
In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this bug.
Please see the Security Errata Policy for further details: htt
Bugzilla
CVE-2020-2181 jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps
bugzilla·2020-06-16·CVSS 6.5
CVE-2020-2181 [MEDIUM] CVE-2020-2181 jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps
CVE-2020-2181 jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps
A vulnerability was found in Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Reference:
http://www.openwall.com/lists/oss-security/2020/05/06/3
Discussion:
External References:
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1374
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 4.4
Via RHSA-2020:3625 https://access.redhat.com/errata/RHSA-2020:3625
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve
2020-05-06
Published