cbcvebase.
CVE-2020-2149
published 2020-03-09

CVE-2020-2149: Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsaudit_trail_plugin
jenkinsbacklog_plugin
jenkinscobertura_plugin
jenkinscredentials_plugin
jenkinscryptomove_plugin
jenkinsdeployhub_plugin
jenkinsgit_plugin
jenkinsliterate_plugin
jenkinslogstash_plugin
jenkinsmac_cloud_host_launched_by_the_plugin
jenkinsmac_plugin
jenkinsopenshift_deployer_plugin
jenkinsp4_plugin
jenkinsquality_gates_plugin
jenkinsrepository_connector<= 1.2.6
jenkinsrepository_connector_plugin
jenkinsrundeck_plugin
jenkinssandbox_protection_in_script_security_plugin
jenkinsscript_security_plugin
jenkinsskytap_cloud_ci_plugin
jenkinssonar_quality_gates_plugin
jenkinssubversion_release_manager_plugin
jenkinstimestamper_plugin
jenkinsyaml_input_files_to_literate_plugin
jenkinszephyr_enterprise_test_management_plugin