CVE-2020-2251: Jenkins
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
Affected products
- Jenkins Jenkins: before 2.236 (fixed in 2.236)
- Jenkins Soapui Pro Functional Testing: up to and including 1.5
Published 2020-09-01. Last modified 2026-06-17.