Cleartext storage of sensitive information in Zephyr Enterprise Test Management - CVE-2020-2145
Published: March 11, 2020
Vulnerability identifier: #VU26015
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2145
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to view the password on the target system.
The vulnerability exists due to the affected software stores its Zephyr password in plain text in the global configuration file "com.thed.zephyr.jenkins.reporter.ZeeReporter.xml". A local user with access to the master file system can obtain this credential.
The vulnerability exists due to the affected software stores its Zephyr password in plain text in the global configuration file "com.thed.zephyr.jenkins.reporter.ZeeReporter.xml". A local user with access to the master file system can obtain this credential.
Affected software
Zephyr Enterprise Test Management
How to mitigate CVE-2020-2145
Install updates from vendor's website.
Zephyr Enterprise Test Management - update to 1.10