PT-2020-15321 · Jenkins · Jenkins S3 Publisher Plugin+1

Wadeck Follonier

·

Published

2020-02-12

·

Updated

2023-10-25

·

CVE-2020-2114

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins S3 publisher Plugin versions 0.11.4 and earlier
Description The issue concerns the transmission of configured credentials in plain text as part of the global Jenkins configuration form, potentially leading to their exposure. This occurs because the S3 Publisher Plugin stores a secret key in its global configuration, which, although stored encrypted on disk, is transmitted in plain text. This can result in exposure of the credential through browser extensions, cross-site scripting vulnerabilities, and similar situations.
Recommendations For Jenkins S3 publisher Plugin versions 0.11.4 and earlier, update to version 0.11.5 or later, which transmits the secret key in its global configuration encrypted.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-2114
GHSA-FFR6-8CV5-J637

Affected Products

Jenkins
Jenkins S3 Publisher Plugin