CVE Published: 01/09/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: jenkins |
Vendor: Jenkins project |
Product: Jenkins Team Foundation Server Plugin Status : PUBLISHED
CVE-2020-2249 Description
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.