PT-2020-15485 · Jenkins · Jenkins Perfecto Plugin+1

Published

2020-09-16

·

Updated

2023-10-25

·

CVE-2020-2260

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Perfecto Plugin versions 1.17 and earlier
Description A missing permission check in the plugin allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials, specifically username and password. This issue arises from the lack of a permission check in a method that implements a connection test.
Recommendations For Jenkins Perfecto Plugin versions 1.17 and earlier, update to version 1.18 or later, which requires Overall/Administer permission to perform a connection test, thereby mitigating the risk.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-2260
GHSA-3H2Q-M63Q-9CF6

Affected Products

Jenkins
Jenkins Perfecto Plugin