CVE-2020-2127

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

4.3medium3.x
0246810

CVSS Score: 4.3/10

All CVSS Scores

CVSS 3.x
4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS 2.0
4.0

Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Description

Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-522

Vulnerable Software (1)

Type: Configuration

Vendor: jenkins

Product: bmc_release_package_and_deployment

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:jenkins:bmc_release_package_and_deployment:*:*:*:*:*:jenkins:*:*",      "versionEndIncluding": "1.1",      "vulnerable": true    }  ],  "oper...

Source: nvd