CVE-2020-2198

Severity
6.5MEDIUM
EPSS
0.0%
top 85.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 24

Description

Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Missing permission check in Jenkins Project Inheritance Plugin2022-05-24
GHSA
Missing permission check in Jenkins Project Inheritance Plugin2022-05-24
CVEList
CVE-2020-2198: Jenkins Project Inheritance Plugin 192020-06-03

💥Exploits & PoCs

1
Exploit-DB
Playable 9.18 iOS - Persistent Cross-Site Scripting2020-04-17

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-06-032020-06-03