CVE-2020-2198

Publication date

2020-06-03 12:40:26

Family

jenkins

State

PUBLISHED

Description

Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the getConfigAsXML API URL when transmitting job config.xml data to users without Job/Configure.