First published: Mon Mar 09 2020(Updated: )
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Skytap Cloud Ci | <=2.07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2157 has a severity level of medium due to the potential exposure of sensitive credentials.
To mitigate CVE-2020-2157, upgrade the Jenkins Skytap Cloud CI Plugin to version 2.08 or later.
CVE-2020-2157 affects all configured credentials transmitted in plain text during job configuration.
There are no public exploits known for CVE-2020-2157, but the vulnerability poses a security risk.
Jenkins Skytap Cloud CI Plugin versions 2.07 and earlier are vulnerable to CVE-2020-2157.