CVE-2020-2129
Description
Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file, exposing it to users with master file system access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file, exposing it to users with master file system access.
Vulnerability
Overview
The Jenkins Eagle Tester Plugin, versions 1.0.9 and earlier, stores a password in plaintext within its global configuration file on the Jenkins master [1][3]. This file is readable by any user with access to the Jenkins master's file system, including those with only file system-level privileges rather than administrative Jenkins permissions.
Attack
Vector and Prerequisites
An attacker who gains access to the Jenkins master's file system—for example, through compromised credentials, another vulnerability, or direct server access—can retrieve the unencrypted password from the plugin's configuration file [1]. No authentication to Jenkins itself is required beyond file system read access, as the password is stored without any encryption or obfuscation.
Impact
Once an attacker obtains this password, they can use it to authenticate to any external service the plugin is configured to connect to, potentially compromising those systems [1]. The severity is considered medium (CVSS base score 5.0) due to the prerequisite of file system access, but the impact can be significant depending on the permissions of the exposed credentials.
Mitigation
Jenkins has released Eagle Tester Plugin version 1.0.10 which encrypts the stored password [1]. Users should update to this version or later. As of the advisory date, no workaround was provided; replacing the password in the configuration manual lacks encryption, so updating the plugin is the recommended remediation [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.mobileenerlytics.eagle.tester:eagle-testerMaven | <= 1.0.9 | — |
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-vj6f-q4w6-qx9pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-2129ghsaADVISORY
- www.openwall.com/lists/oss-security/2020/02/12/3ghsamailing-listx_refsource_MLISTWEB
- jenkins.io/security/advisory/2020-02-12/ghsax_refsource_CONFIRMWEB
News mentions
1- Jenkins Security Advisory 2020-02-12Jenkins Security Advisories · Feb 12, 2020