Unencrypted Webhook Secret Exposure in Jenkins Team Foundation Server Plugin
CVE-2020-2249
3.3LOW
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 1 September 2020
Summary
The Jenkins Team Foundation Server Plugin prior to version 5.157.1 has a security vulnerability where it stores a webhook secret unencrypted in its global configuration file on the Jenkins controller. This potentially allows attackers with access to the Jenkins controller's file system to view the sensitive information, leading to unauthorized access to the webhooks configured in Jenkins.
Affected Version(s)
Jenkins Team Foundation Server Plugin <= 5.157.1
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved