Vulnerability Description
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Sms Notification | <= 1.2 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2020/10/08/5Mailing ListThird Party Advisory
- https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2054Vendor Advisory
- http://www.openwall.com/lists/oss-security/2020/10/08/5Mailing ListThird Party Advisory
- https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-2054Vendor Advisory
FAQ
What is CVE-2020-2297?
CVE-2020-2297 is a vulnerability with a CVSS score of 3.3 (LOW). Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins...
How severe is CVE-2020-2297?
CVE-2020-2297 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-2297?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Sms Notification.