PT-2020-15455 · Jenkins · Jenkins Pipeline Maven Integration Plugin+1

Tim Jacomb

·

Published

2020-08-12

·

Updated

2023-10-25

·

CVE-2020-2234

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Pipeline Maven Integration Plugin versions 3.8.2 and earlier
Description A missing permission check in the plugin allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs, potentially capturing credentials stored in Jenkins. The form validation method is also vulnerable to cross-site request forgery (CSRF) as it does not require POST requests.
Recommendations For Jenkins Pipeline Maven Integration Plugin versions 3.8.2 and earlier, update to version 3.8.3 or later, which requires POST requests and Job/Configure permission for the affected form validation method, mitigating the issue.

Fix

Improper Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-2234
GHSA-MRR8-FCG7-P2WG

Affected Products

Jenkins
Jenkins Pipeline Maven Integration Plugin