PT-2020-15400 · Jenkins · Jenkins Amazon Ec2 Plugin+1
Oleg Nenashev
·
Published
2020-05-06
·
Updated
2023-10-25
·
CVE-2020-2186
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Amazon EC2 Plugin versions 1.50.1 and earlier
Description
A cross-site request forgery issue allows attackers to provision instances. The vulnerability is due to the plugin not requiring POST requests in several HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities. This allows an attacker to provision instances with an attacker-specified template ID.
Recommendations
For Jenkins Amazon EC2 Plugin versions 1.50.1 and earlier, update to version 1.50.2 or later, which requires POST requests for the affected HTTP endpoints.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Amazon Ec2 Plugin