PT-2020-15353 · Jenkins · Jenkins P4 Plugin+1

Wadeck Follonier

·

Published

2020-03-09

·

Updated

2023-10-25

·

CVE-2020-2142

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins P4 Plugin versions 1.10.10 and earlier
Description A missing permission check in the Jenkins P4 Plugin allows attackers with Overall/Read permission to trigger builds or add labels in the Perforce repository.
Recommendations For Jenkins P4 Plugin versions 1.10.10 and earlier, update to version 1.10.11 to ensure appropriate user permissions for the affected HTTP endpoints.

Fix

Cleartext Transmission of Sensitive Information

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-2142
GHSA-F9V6-P7HP-C3QX

Affected Products

Jenkins
Jenkins P4 Plugin