Executive brief
Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin
Affected products
- Maven org.jenkins-ci.plugins:fortify-on-demand-uploader
Junglewise Threat Intelligence
CVE-2020-2202 · Severity: low · CVSS 3.1 · Published 2022-05-24
Technologies: org.jenkins-ci.plugins:fortify-on-demand-uploader (Maven). Vendors: Maven.
Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin