CVE-2020-2274: Medium severity jenkins vulnerability
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2274?
CVE-2020-2274 is considered a high severity vulnerability due to the exposure of unencrypted credentials.
How do I fix CVE-2020-2274?
To fix CVE-2020-2274, upgrade the Jenkins ElasTest Plugin to version 1.2.2 or later, where the vulnerability is addressed.
What are the risks associated with CVE-2020-2274?
The risks associated with CVE-2020-2274 include unauthorized access to sensitive information stored in the Jenkins configuration file.
Who is affected by CVE-2020-2274?
CVE-2020-2274 affects users of Jenkins ElasTest Plugin versions 1.2.1 and earlier.
What does CVE-2020-2274 expose?
CVE-2020-2274 exposes the server password as it is stored unencrypted in the global configuration file of Jenkins.