PT-2020-15455 · Jenkins · Jenkins Pipeline Maven Integration Plugin+1
Tim Jacomb
·
Published
2020-08-12
·
Updated
2023-10-25
·
CVE-2020-2234
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Pipeline Maven Integration Plugin versions 3.8.2 and earlier
Description
A missing permission check in the plugin allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs, potentially capturing credentials stored in Jenkins. The form validation method is also vulnerable to cross-site request forgery (CSRF) as it does not require POST requests.
Recommendations
For Jenkins Pipeline Maven Integration Plugin versions 3.8.2 and earlier, update to version 3.8.3 or later, which requires POST requests and Job/Configure permission for the affected form validation method, mitigating the issue.
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Jenkins Pipeline Maven Integration Plugin