CVE-2020-2319: Medium severity jenkins vmware lab manager slaves vulnerability
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-2319.
What is the title of this vulnerability?
The title of this vulnerability is 'Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.'
What is the severity of CVE-2020-2319?
The severity of CVE-2020-2319 is medium with a CVSS score of 6.5.
How does CVE-2020-2319 affect Jenkins VMware Lab Manager Slaves Plugin?
CVE-2020-2319 affects Jenkins VMware Lab Manager Slaves Plugin version 0.2.8 and earlier.
How can the password vulnerability be exploited?
The password vulnerability can be exploited by users with access to the Jenkins controller file system who can view the unencrypted password stored in the global config.xml file.