Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.
Credentials Binding Plugin 687.689.v1a_f775332fc9 rethrows exceptions that contain credentials, masking those credentials in the error messages.
{
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2025-07-09T16:15:24Z",
"cwe_ids": [
"CWE-522",
"CWE-779"
],
"github_reviewed_at": "2025-07-09T20:28:31Z"
}