Junglewise Threat Intelligence

CVE-2020-2202: Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin

CVE-2020-2202 · Severity: low · CVSS 3.1 · Published 2022-05-24

Technologies: org.jenkins-ci.plugins:fortify-on-demand-uploader (Maven). Vendors: Maven.

Executive brief

Users with Overall/Read access could enumerate credentials IDs in Jenkins Fortify on Demand Plugin

Affected products

  • Maven org.jenkins-ci.plugins:fortify-on-demand-uploader

Related threats