CVE-2020-2249: Low severity microsoft team foundation server vulnerability
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Other sources
tfs Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file hudson.plugins.tfs.TeamPluginGlobalConfig.xml on the Jenkins controller as part of its configuration. This secret can be viewed by attackers with access to the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-2249.
What is the title of the vulnerability?
The title of the vulnerability is 'Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its...'
What is the description of the vulnerability?
The vulnerability allows attackers with access to the Jenkins controller file system to view an unencrypted webhook secret stored in a global configuration file.
What is the affected software?
The affected software is Jenkins Team Foundation Server Plugin version 5.157.1 and earlier.
What is the severity of this vulnerability?
The severity of the vulnerability is low, with a severity score of 3.3.