Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
Moderate severity
GitHub Reviewed
Published
Jul 9, 2025
to the GitHub Advisory Database
•
Updated Jul 9, 2025
Package
Affected versions
< 687.689.v1a
Patched versions
687.689.v1a
Description
Published by the National Vulnerability Database
Jul 9, 2025
Published to the GitHub Advisory Database
Jul 9, 2025
Reviewed
Jul 9, 2025
Last updated
Jul 9, 2025
Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.
Credentials Binding Plugin 687.689.v1a_f775332fc9 rethrows exceptions that contain credentials, masking those credentials in the error messages.
References