CVE-2020-2218 describes a vulnerability in Jenkins HP ALM Quality Center Plugin versions 1.6 and earlier. This flaw involves the plugin storing a password in an unencrypted format within its global configuration file on the Jenkins master, making it accessible to users with file system access. Rated with a CVSS score of 3.3 (LOW), the vulnerability requires local access and low privileges, with a potential impact of information disclosure (confidentiality). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6CPE matchmatch criteria | cpe:2.3:a:hp_application_lifecycle_management_quality_center_project:hp_application_lifecycle_management_quality_center:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.