CVE-2020-2181: Jenkins Credentials Binding

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

Affected products

  • Jenkins Credentials Binding: up to and including 1.22

Published 2020-05-06. Last modified 2026-06-17.