Unmasked Secrets in Jenkins Build Logs

Unmasked Secrets in Jenkins Build Logs

CVE-2020-2181 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

Learn more about our Cis Benchmark Audit For Bind.