PT-2020-15400 · Jenkins · Jenkins Amazon Ec2 Plugin+1

Oleg Nenashev

·

Published

2020-05-06

·

Updated

2023-10-25

·

CVE-2020-2186

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Amazon EC2 Plugin versions 1.50.1 and earlier
Description A cross-site request forgery issue allows attackers to provision instances. The vulnerability is due to the plugin not requiring POST requests in several HTTP endpoints, resulting in cross-site request forgery (CSRF) vulnerabilities. This allows an attacker to provision instances with an attacker-specified template ID.
Recommendations For Jenkins Amazon EC2 Plugin versions 1.50.1 and earlier, update to version 1.50.2 or later, which requires POST requests for the affected HTTP endpoints.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2186
GHSA-W6HW-57JQ-H7F5

Affected Products

Jenkins
Jenkins Amazon Ec2 Plugin