PT-2020-15326 · Jenkins · Jenkins Azure Ad Plugin+1

Jetersen

+1

·

Published

2020-02-12

·

Updated

2023-10-25

·

CVE-2020-2119

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Azure AD Plugin versions 1.1.2 and earlier
Description The issue concerns the transmission of configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. Specifically, the Azure AD Plugin stores a client secret in its global configuration, which, although stored encrypted on disk, is transmitted in plain text by versions 1.1.2 and earlier. This can lead to credential exposure through browser extensions, cross-site scripting vulnerabilities, and similar situations.
Recommendations For Jenkins Azure AD Plugin versions 1.1.2 and earlier, update to version 1.2.0 or later, which transmits the client secret in its global configuration encrypted. As a temporary workaround, consider restricting access to the global Jenkins configuration form to minimize the risk of exposure.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-2119
GHSA-VVG2-HG3C-MQJ3

Affected Products

Jenkins
Jenkins Azure Ad Plugin