cbcvebase.
CVE-2020-2314
published 2020-11-04

CVE-2020-2314: Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Affected

19 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory_plugin
jenkinsansible_plugin
jenkinsappspider<= 1.0.12
jenkinsappspider_plugin
jenkinsauthentication_cache_in_active_directory_plugin
jenkinsaws_global_configuration_plugin
jenkinsazure_key_vault_plugin
jenkinsfindbugs_plugin
jenkinsids_in_azure_key_vault_plugin
jenkinsjenkins-ci_plugin
jenkinskubernetes_plugin
jenkinsmail_commander_plugin
jenkinsmercurial_plugin
jenkinssqlplus_script_runner_plugin
jenkinsstatic_analysis_utilities_plugin
jenkinssubversion_plugin
jenkinsvisualworks_store_plugin
jenkinsvmware_lab_manager_slaves_plugin
jenkins_projectjenkins_appspider_pluginunspecified – 1.0.12