CVE-2020-2181: Infoleak
A vulnerability was found in Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Reference: http://www.openwall.com/lists/oss-security/2020/05/06/3
Other sources
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Jenkins Credentials Binding Plugin 1.23 now masks secrets when the build contains no build steps.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2181?
CVE-2020-2181 has a low severity rating due to the lack of risk involved in exposure.
How do I fix CVE-2020-2181?
To fix CVE-2020-2181, upgrade the Jenkins Credentials Binding Plugin to version 1.23 or later.
What systems are affected by CVE-2020-2181?
CVE-2020-2181 affects all versions of the Jenkins Credentials Binding Plugin prior to version 1.23.
What happens if I don’t address CVE-2020-2181?
Ignoring CVE-2020-2181 could lead to sensitive information leakage in build logs under specific circumstances.
Are there workarounds for CVE-2020-2181?
There are no official workarounds for CVE-2020-2181; updating to the latest version is recommended.