Identifier

CVE-2020-2239

Package Slug

maven/org.jenkins-ci.plugins/Parameterized-Remote-Trigger

Vulnerability

Missing Encryption of Sensitive Data

Description

The Jenkins Parameterized Remote Trigger Plugin stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

Affected Versions

All versions up to 3.1.3

Solution

Upgrade to version 3.1.4 or above.

Last Modified

2020-09-04

source