GHSA-9768-hprv-crj5

Suggest an improvement
Source
https://github.com/advisories/GHSA-9768-hprv-crj5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-9768-hprv-crj5/GHSA-9768-hprv-crj5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9768-hprv-crj5
Aliases
Published
2025-07-09T18:30:44Z
Modified
2025-11-05T20:36:03.150707Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
Details

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.

Credentials Binding Plugin 687.689.v1a_f775332fc9 rethrows exceptions that contain credentials, masking those credentials in the error messages.

Database specific
{
    "severity": "MODERATE",
    "github_reviewed": true,
    "nvd_published_at": "2025-07-09T16:15:24Z",
    "cwe_ids": [
        "CWE-522",
        "CWE-779"
    ],
    "github_reviewed_at": "2025-07-09T20:28:31Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:credentials-binding

Package

Name
org.jenkins-ci.plugins:credentials-binding
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/credentials-binding

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
687.689.v1a

Affected versions

1.*
1.0-beta-1
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.19
1.20
1.20.1
1.21
1.22
1.23
1.24
1.24.1
1.25
1.26
1.27
1.27.1
523.*
523.vd859a_4b_122e6
523.525.vb_72269281873
604.*
604.vb_64480b_c56ca_
621.*
621.v58c0fb_d285a_c
626.*
626.v8d9034b_8ea_cc
631.*
631.v861c06d062b_4
636.*
636.v55f1275c7b_27
642.*
642.v737c34dea_6c2
657.*
657.v2b_19db_7d6e6d
677.*
677.vdc9d38cb_254d
679.*
679.v6288482e873c
681.*
681.vf91669a_32e45
687.*
687.v619cb_15e923f

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-9768-hprv-crj5/GHSA-9768-hprv-crj5.json"