CVE-2020-2095

MEDIUM

Jenkins Redgate SQL Change Automation Plugin < 2.0.4 - Insufficiently Protected Credentials in Job Config

Title source: llm
STIX 2.1

Description

Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-522
Status published
Products (2)
com.redgate.plugins.redgatesqlci/redgate-sql-ci 0 - 2.0.5Maven
jenkins/redgate_sql_change_automation < 2.0.4
Published Jan 15, 2020
Tracked Since Feb 18, 2026