PT-2020-15312 · Jenkins · Jenkins
Michele Romano
·
Published
2020-01-29
·
Updated
2024-03-06
·
CVE-2020-2105
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.218 and earlier
Jenkins LTS versions 2.204.1 and earlier
Description
The issue allows for clickjacking attacks due to the absence of the
X-Frame-Options: deny HTTP header in REST API responses. An attacker could exploit this by tricking a user into performing an action on a specially crafted web page that embeds a REST API endpoint in an iframe, potentially allowing the attacker to learn the content of that endpoint.Recommendations
For Jenkins versions 2.218 and earlier, update to version 2.219 or later.
For Jenkins LTS versions 2.204.1 and earlier, update to version 2.204.2 or later.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins