CVE-2020-2107
published 2020-01-29CVE-2020-2107: Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.65%
46.9th percentile
Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | code_coverage_plugin | — | — |
| jenkins | fortify | <= 19.1.29 | — |
| jenkins | fortify_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | websphere_deployer_plugin | — | — |
| jenkins_project | jenkins_fortify_plugin | unspecified – 19.1.29 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Fortify Plugin stored credentials in plain text
ghsa·2022-05-24
CVE-2020-2107 [MEDIUM] CWE-256 Fortify Plugin stored credentials in plain text
Fortify Plugin stored credentials in plain text
Fortify Plugin 19.1.29 and earlier stored its proxy server password unencrypted in job `config.xml` files. This password could be read by users with the Extended Read permission.
Fortify Plugin 19.2.30 now encrypts the proxy server password.
OSV
Fortify Plugin stored credentials in plain text
osv·2022-05-24
CVE-2020-2107 [MEDIUM] Fortify Plugin stored credentials in plain text
Fortify Plugin stored credentials in plain text
Fortify Plugin 19.1.29 and earlier stored its proxy server password unencrypted in job `config.xml` files. This password could be read by users with the Extended Read permission.
Fortify Plugin 19.2.30 now encrypts the proxy server password.
Jenkins
Jenkins Security Advisory 2020-01-29
vendor_jenkins·2020-01-29·CVSS 8.6
CVE-2020-2099 [HIGH] Jenkins Security Advisory 2020-01-29
Title: Jenkins Security Advisory 2020-01-29
Jenkins Security Advisory 2020-01-29
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Code Coverage
Plugin
Fortify
Plugin
WebSphere Deployer
Plugin
Descriptions
Inbound TCP Agent Protocol/3 authentication bypass
SECURITY-1682
/
CVE-2020-2099
Se
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1758 keycloak: improper verification of certificate with host mismatch could result in information disclosure
bugzilla·2020-03-11·CVSS 5.3
CVE-2020-1758 [MEDIUM] CVE-2020-1758 keycloak: improper verification of certificate with host mismatch could result in information disclosure
CVE-2020-1758 keycloak: improper verification of certificate with host mismatch could result in information disclosure
Keycloak does not perform TLS hostname verification when sending emails via an SMTP server which could result in information disclosure.
External Reference:
https://issues.redhat.com/browse/KEYCLOAK-13285
Discussion:
Mitigation:
Turn off all kinds of email notifications including password reset mails.
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 7
Via RHSA-2020:2107 https://access.redhat.com/errata/RHSA-2020:2107
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 6
Via RHSA-2020:2106 https://access.redhat.com/errata/RHSA-2020:2106
---
This issue has been addres
Bugzilla
CVE-2020-1724 keycloak: problem with privacy after user logout
bugzilla·2020-02-07·CVSS 4.3
CVE-2020-1724 [MEDIUM] CVE-2020-1724 keycloak: problem with privacy after user logout
CVE-2020-1724 keycloak: problem with privacy after user logout
Personal information contained in the Account Manager section can be shown to a user about another user already disconnected (logout) by the keycloak platform.
Reference : https://issues.jboss.org/browse/KEYCLOAK-10641
Discussion:
Acknowledgments:
Name: Francesco Cusinato
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 7
Via RHSA-2020:2107 https://access.redhat.com/errata/RHSA-2020:2107
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 6
Via RHSA-2020:2106 https://access.redhat.com/errata/RHSA-2020:2106
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 8
Via RHSA-2020:21
Bugzilla
CVE-2020-1718 keycloak: security issue on reset credential flow
bugzilla·2020-01-31·CVSS 7.1
CVE-2020-1718 [HIGH] CVE-2020-1718 keycloak: security issue on reset credential flow
CVE-2020-1718 keycloak: security issue on reset credential flow
If the reset flow contains alternative subflow, it may be possible to connect to your application without credentials.
for more information : https://issues.redhat.com/browse/KEYCLOAK-11735
Discussion:
Mitigation:
Disable reset credential flow.
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 7
Via RHSA-2020:2107 https://access.redhat.com/errata/RHSA-2020:2107
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 6
Via RHSA-2020:2106 https://access.redhat.com/errata/RHSA-2020:2106
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3 for RHEL 8
Via RHSA-2020:2108 https://access.redhat.co
2020-01-29
Published