CVE-2020-2132

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 1
Advisories 2

Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

Weaknesses
CWE-522
Insufficiently Protected Credentials
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2020-02-12 15:15:14
(4 years ago)
Updated Date
2023-10-25 18:16:31
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Parasoft Environment Manager for Jenkins 2.14 and prior versions cpe:2.3:a:jenkins:parasoft_environment_manager::*:*:*:*:jenkins <= 2.14
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...