PT-2020-15474 · Readyapi+1 · Readyapi Functional Testing Plugin+2

Published

2020-09-01

·

Updated

2023-10-25

·

CVE-2020-2250

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins SoapUI Pro Functional Testing Plugin versions 1.3 and earlier ReadyAPI Functional Testing Plugin versions 1.3 and earlier
Description The issue concerns the storage of project passwords in an unencrypted manner within job config.xml files on the Jenkins controller. This allows attackers with Extended Read permission or access to the Jenkins controller file system to view these passwords.
Recommendations For Jenkins SoapUI Pro Functional Testing Plugin versions 1.3 and earlier, consider updating to a version where passwords are stored encrypted. For ReadyAPI Functional Testing Plugin versions 1.3 and earlier, update to version 1.4 and save affected job configurations again to encrypt project passwords. As a temporary workaround, consider restricting access to the Jenkins controller file system and limiting Extended Read permission to minimize the risk of exploitation.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2020-2250
GHSA-CCWP-633J-G29V

Affected Products

Jenkins
Jenkins Soapui Pro Functional Testing Plugin
Readyapi Functional Testing Plugin