cbcvebase.
CVE-2020-2209
published 2020-07-02

CVE-2020-2209: Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.69%
48.7th percentile
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

Affected

18 ranges
VendorProductVersion rangeFixed in
jenkinscd_plugin
jenkinscompatibility_action_storage_plugin
jenkinsfortify_on_demand_plugin
jenkinsgithub_coverage_reporter_plugin
jenkinshp_alm_quality_center_plugin
jenkinsids_in_fortify_on_demand_plugin
jenkinsids_to_allow_users_configuring_the_plugin
jenkinslink_column_plugin
jenkinsslack_upload_plugin
jenkinssonargraph_integration_plugin
jenkinsstash_branch_parameter_plugin
jenkinstestcomplete_support<= 2.4.1
jenkinstestcomplete_support_plugin
jenkinsvncrecorder_plugin
jenkinsvncviewer_plugin
jenkinszap_pipeline_plugin
jenkinszephyr_for_jira_test_management_plugin
jenkins_projectjenkins_testcomplete_support_pluginunspecified – 2.4.1

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.