Plain Text Credential Exposure in Jenkins Skytap Cloud CI Plugin
CVE-2020-2157

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
9 March 2020

Summary

The Jenkins Skytap Cloud Continuous Integration Plugin versions 2.07 and earlier are vulnerable to a security issue where configured credentials are transmitted in plain text within job configuration forms. This flaw leads to potential exposure of sensitive credentials, making it easier for unauthorized individuals to access restricted systems. Users are advised to upgrade to the latest version of the plugin to mitigate this vulnerability.

Affected Version(s)

Jenkins Skytap Cloud CI Plugin <= 2.07

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.