cbcvebase.
CVE-2020-2319
published 2020-11-04

CVE-2020-2319: Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can…

PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.03%
59.8th percentile
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Affected

19 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory_plugin
jenkinsansible_plugin
jenkinsappspider_plugin
jenkinsauthentication_cache_in_active_directory_plugin
jenkinsaws_global_configuration_plugin
jenkinsazure_key_vault_plugin
jenkinsfindbugs_plugin
jenkinsids_in_azure_key_vault_plugin
jenkinsjenkins-ci_plugin
jenkinskubernetes_plugin
jenkinsmail_commander_plugin
jenkinsmercurial_plugin
jenkinssqlplus_script_runner_plugin
jenkinsstatic_analysis_utilities_plugin
jenkinssubversion_plugin
jenkinsvisualworks_store_plugin
jenkinsvmware_lab_manager_slaves<= 0.2.8
jenkinsvmware_lab_manager_slaves_plugin
jenkins_projectjenkins_vmware_lab_manager_slaves_pluginunspecified – 0.2.8

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.