VulnerabilityModified
CVE-2020-2198
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.
MEDIUM 6.5EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.80% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- jenkins/project inheritance
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2020/06/03/3Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1582Vendor Advisory
- http://www.openwall.com/lists/oss-security/2020/06/03/3Mailing List, Third Party Advisory
- https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1582Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.