Plain Text Credential Exposure in Jenkins Skytap Cloud CI Plugin
CVE-2020-2157
4.3MEDIUM
Summary
The Jenkins Skytap Cloud Continuous Integration Plugin versions 2.07 and earlier are vulnerable to a security issue where configured credentials are transmitted in plain text within job configuration forms. This flaw leads to potential exposure of sensitive credentials, making it easier for unauthorized individuals to access restricted systems. Users are advised to upgrade to the latest version of the plugin to mitigate this vulnerability.
Affected Version(s)
Jenkins Skytap Cloud CI Plugin <= 2.07
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved