Medium severity6.5NVD Advisory· Published May 6, 2020· Updated Jun 17, 2026
CVE-2020-2181
CVE-2020-2181
Description
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:credentials-bindingMaven | < 1.23 | 1.23 |
Affected products
3- cpe:2.3:a:jenkins:credentials_binding:*:*:*:*:*:jenkins:*:*Range: <=1.22
- Range: unspecified
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/05/06/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-43j2-r4v3-m8jpghsaADVISORY
- jenkins.io/security/advisory/2020-05-06/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-2181ghsaADVISORY
- github.com/jenkinsci/credentials-binding-plugin/commit/59ead11bcb3fd132258d1d7da4a34d47750f40d2ghsaWEB
News mentions
1- Jenkins Security Advisory 2020-05-06Jenkins Security Advisories · May 6, 2020