cbcvebase.
CVE-2020-2249
published 2020-09-01

CVE-2020-2249: Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where…

PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.26%
17.1th percentile
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsbuild_failure_analyzer_plugin
jenkinscadence_vmanager_plugin
jenkinsdatabase_plugin
jenkinsgit_parameter_plugin
jenkinsjsgames_plugin
jenkinsklocwork_analysis_plugin
jenkinsklocwork_plugin
jenkinsparameterized_remote_trigger_plugin
jenkinsreadyapi_functional_testing_plugin
jenkinsteam_foundation_server<= 5.157.1
jenkinsvalgrind_plugin
jenkins_projectjenkins_team_foundation_server_pluginunspecified – 5.157.1

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.