First published: Wed Nov 04 2020(Updated: )
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Vmware Lab Manager Slaves | <=0.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-2319.
The title of this vulnerability is 'Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.'
The severity of CVE-2020-2319 is medium with a CVSS score of 6.5.
CVE-2020-2319 affects Jenkins VMware Lab Manager Slaves Plugin version 0.2.8 and earlier.
The password vulnerability can be exploited by users with access to the Jenkins controller file system who can view the unencrypted password stored in the global config.xml file.