Vulnerability Details CVE-2020-2181
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-2181
-
cpe:2.3:a:jenkins:credentials_binding:1.0
-
cpe:2.3:a:jenkins:credentials_binding:1.1
-
cpe:2.3:a:jenkins:credentials_binding:1.10
-
cpe:2.3:a:jenkins:credentials_binding:1.11
-
cpe:2.3:a:jenkins:credentials_binding:1.12
-
cpe:2.3:a:jenkins:credentials_binding:1.13
-
cpe:2.3:a:jenkins:credentials_binding:1.14
-
cpe:2.3:a:jenkins:credentials_binding:1.15
-
cpe:2.3:a:jenkins:credentials_binding:1.16
-
cpe:2.3:a:jenkins:credentials_binding:1.17
-
cpe:2.3:a:jenkins:credentials_binding:1.18
-
cpe:2.3:a:jenkins:credentials_binding:1.19
-
cpe:2.3:a:jenkins:credentials_binding:1.2
-
cpe:2.3:a:jenkins:credentials_binding:1.20
-
cpe:2.3:a:jenkins:credentials_binding:1.20.1
-
cpe:2.3:a:jenkins:credentials_binding:1.21
-
cpe:2.3:a:jenkins:credentials_binding:1.22
-
cpe:2.3:a:jenkins:credentials_binding:1.3
-
cpe:2.3:a:jenkins:credentials_binding:1.4
-
cpe:2.3:a:jenkins:credentials_binding:1.5
-
cpe:2.3:a:jenkins:credentials_binding:1.6
-
cpe:2.3:a:jenkins:credentials_binding:1.7
-
cpe:2.3:a:jenkins:credentials_binding:1.8
-
cpe:2.3:a:jenkins:credentials_binding:1.9