CVE-2020-2249

CVSS v3.1 3.3 (Low)
33% Progress
CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.04 % (13th)
0.04% Progress
Affected Products 1
Advisories 2

Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

Weaknesses
CWE-311
Missing Encryption of Sensitive Data
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2020-09-01 14:15:13
(4 years ago)
Updated Date
2023-10-25 18:16:39
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Team Foundation Server for Jenkins 5.157.1 and prior versions cpe:2.3:a:jenkins:team_foundation_server::*:*:*:*:jenkins <= 5.157.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...