{"api_version":"1","generated_at":"2026-07-23T10:55:01+00:00","cve":"CVE-2020-2212","urls":{"html":"https://cve.report/CVE-2020-2212","api":"https://cve.report/api/cve/CVE-2020-2212.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-2212","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-2212"},"summary":{"title":"CVE-2020-2212","description":"Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.","state":"PUBLIC","assigner":"jenkinsci-cert@googlegroups.com","published_at":"2020-07-02 15:15:00","updated_at":"2023-10-25 18:16:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2020/07/02/7","name":"[oss-security] 20200702 Multiple vulnerabilities in Jenkins plugins","refsource":"MLIST","tags":["Third Party Advisory"],"title":"oss-security - Multiple vulnerabilities in Jenkins plugins","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1632","name":"https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1632","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Jenkins Security Advisory 2020-07-02","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-2212","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-2212","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"2212","vulnerable":"1","versionEndIncluding":"1.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jenkins","cpe5":"github_coverage_reporter","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"jenkins","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2020-2212","ASSIGNER":"jenkinsci-cert@googlegroups.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Jenkins project","product":{"product_data":[{"product_name":"Jenkins GitHub Coverage Reporter Plugin","version":{"version_data":[{"version_value":"not down converted","x_cve_json_5_version_data":{"versions":[{"lessThanOrEqual":"1.8","status":"affected","version":"unspecified","versionType":"custom"},{"lessThan":"unspecified","status":"unknown","version":"next of 1.8","versionType":"custom"}]}}]}}]}}]}},"references":{"reference_data":[{"url":"https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1632","refsource":"MISC","name":"https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1632"},{"url":"http://www.openwall.com/lists/oss-security/2020/07/02/7","refsource":"MISC","name":"http://www.openwall.com/lists/oss-security/2020/07/02/7"}]}},"nvd":{"publishedDate":"2020-07-02 15:15:00","lastModifiedDate":"2023-10-25 18:16:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jenkins:github_coverage_reporter:*:*:*:*:*:jenkins:*:*","versionEndIncluding":"1.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"2212","Ordinal":"161684","Title":"CVE-2020-2212","CVE":"CVE-2020-2212","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"2212","Ordinal":"1","NoteData":"Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"2212","Ordinal":"2","NoteData":"2020-07-02","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"2212","Ordinal":"3","NoteData":"2020-07-02","Type":"Other","Title":"Modified"}]}}}