PT-2020-15311 · Cloudbees+1 · Jenkins

Daniel Beck

·

Published

2020-01-29

·

Updated

2024-03-06

·

CVE-2020-2104

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.218 and earlier Jenkins LTS versions 2.204.1 and earlier
Description The issue allows users with Overall/Read access to view a JVM memory usage chart, which could potentially disclose sensitive information about the system's memory usage. This access requires no permissions beyond the general Overall/Read, allowing non-administrator users to view JVM memory usage data.
Recommendations For Jenkins versions 2.218 and earlier, update to version 2.219 or later to require Overall/Administer permissions to view the JVM memory usage chart. For Jenkins LTS versions 2.204.1 and earlier, update to version 2.204.2 or later to require Overall/Administer permissions to view the JVM memory usage chart.

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2020-2104
CVE-2020-2104
GHSA-R78Q-QGX6-64PP

Affected Products

Jenkins