CVE-2020-2124

Severity
4.3MEDIUM
EPSS
0.0%
top 91.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 24

Description

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

🔴Vulnerability Details

8
OSV
Password stored in plain text by Dynamic Extended Choice Parameter Plugin2022-05-24
GHSA
Password stored in plain text by Dynamic Extended Choice Parameter Plugin2022-05-24
OSV
samba regression2021-12-13
OSV
samba regression2021-12-13
OSV
samba vulnerabilities2021-12-06

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-02-122020-02-12