Unencrypted Storage of Webhook Secret in Jenkins Team Foundation Server Plugin
CVE-2020-2249 · LOW Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Learn more about our Web App Pen Testing.