Jenkins / Credentials Binding
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-48922 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers a… | HIGH | 7.5 | May 27, 2026 |
| CVE-2026-42520 | Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to pr… | HIGH | 7.5 | Apr 29, 2026 |
| CVE-2025-53650 | Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error… | MEDIUM | 5.3 | Jul 9, 2025 |
| CVE-2022-20616 | jenkins-2-plugins/credentials-binding: does not perform a permission check in a method implementing form validation | MEDIUM | 4.3 | Jan 12, 2022 |
| CVE-2020-2182 | jenkins-credentials-binding-plugin: improper masking of secrets | MEDIUM | 4.3 | May 6, 2020 |
| CVE-2020-2181 | jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps | MEDIUM | 6.5 | May 6, 2020 |
| CVE-2019-1010241 | jenkins-plugin-credentials-binding: storing passwords in recoverable format leading to authenticated users being able to recover credentials | MEDIUM | 6.5 | Jul 19, 2019 |
| CVE-2018-1000057 | jenkins-plugin-credentials-binding: improper masking of the secret provided to the build in rare circumstances | MEDIUM | 5.3 | Feb 9, 2018 |
Showing 1 to 8 of 8 CVEs