Unencrypted Storage of Webhook Secret in Jenkins Team Foundation Server Plugin

Unencrypted Storage of Webhook Secret in Jenkins Team Foundation Server Plugin

CVE-2020-2249 · LOW Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

Learn more about our Web App Pen Testing.