
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-2251 affects the Jenkins SoapUI Pro Functional Testing Plugin versions 1.5 and earlier. The vulnerability was discovered and disclosed on September 1, 2020. The issue involves the transmission of project passwords in plain text as part of the global configuration form, despite being stored encrypted on disk since version 1.4. This vulnerability specifically affects Jenkins installations before version 2.236, including 2.235.x LTS (Jenkins Advisory).
The vulnerability has a CVSS v3.1 Base Score of 4.3 (Medium), with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. The core issue lies in how the plugin handles project passwords in the job config.xml files on the Jenkins controller. While these passwords are stored in encrypted form on disk since version 1.4, they are transmitted in plain text when displayed in the global configuration form in versions 1.5 and earlier (NVD).
The vulnerability allows attackers with Extended Read permission to view project passwords when they are transmitted in plain text through the global configuration form. This exposure of sensitive credentials could potentially lead to unauthorized access to project resources (Jenkins Advisory).
The vulnerability requires an attacker to have Extended Read permission on the Jenkins instance to exploit. The attack vector is network-based with low attack complexity, requiring low privileges and no user interaction (NVD).
As of the advisory's publication, there was no direct fix available for this vulnerability. However, upgrading to Jenkins 2.236 or later provides protection as it introduces a security hardening feature that transparently encrypts and decrypts data used for Jenkins password form fields (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."