PT-2020-15397 · Jenkins · Jenkins Cas Plugin+1

Oleg Nenashev

·

Published

2020-05-06

·

Updated

2023-10-25

·

CVE-2020-2184

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins CVS Plugin versions 2.15 and earlier
Description A cross-site request forgery issue allows attackers to create and manipulate tags, and to connect to an attacker-specified URL, by exploiting HTTP endpoints that do not require POST requests. This enables attackers to perform unauthorized actions.
Recommendations For Jenkins CVS Plugin versions 2.15 and earlier, update to version 2.16 or later, which requires POST requests for the affected HTTP endpoints, mitigating the cross-site request forgery risk.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-2184
GHSA-63MW-HP3H-GC77

Affected Products

Jenkins
Jenkins Cas Plugin