Unencrypted Webhook Secret Exposure in Jenkins Team Foundation Server Plugin
CVE-2020-2249

3.3LOW

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
1 September 2020

Summary

The Jenkins Team Foundation Server Plugin prior to version 5.157.1 has a security vulnerability where it stores a webhook secret unencrypted in its global configuration file on the Jenkins controller. This potentially allows attackers with access to the Jenkins controller's file system to view the sensitive information, leading to unauthorized access to the webhooks configured in Jenkins.

Affected Version(s)

Jenkins Team Foundation Server Plugin <= 5.157.1

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.