CVE-2020-2314: Jenkins Appspider

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Affected products

  • Jenkins Appspider: up to and including 1.0.12

Published 2020-11-04. Last modified 2026-06-17.