PT-2020-15334 · Jenkins · Jenkins Digitalocean Plugin+1

James Holderness

·

Published

2020-02-12

·

Updated

2023-10-25

·

CVE-2020-2126

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins DigitalOcean Plugin version 1.1 and earlier
Description The issue concerns the storage of a token in an unencrypted form within the global config.xml file on the Jenkins master. This token can be accessed by users who have permission to view the master file system.
Recommendations For Jenkins DigitalOcean Plugin version 1.1 and earlier, consider restricting access to the global config.xml file to minimize the risk of token exposure until a patch is available.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2020-2126
GHSA-8G6V-G8QC-5W7J

Affected Products

Jenkins
Jenkins Digitalocean Plugin