A vulnerability was found in Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a $ character in some circumstances.
Reference: http://www.openwall.com/lists/oss-security/2020/05/06/3
A vulnerability was found in Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Reference: http://www.openwall.com/lists/oss-security/2020/05/06/3