PT-2020-15516 · Jenkins · Jenkins Role-Based Authorization Strategy Plugin+1

·

CVE-2020-2286

·

Published

2020-10-08

·

Updated

2023-10-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Role-based Authorization Strategy Plugin versions 3.0 and earlier
Description The issue arises from the improper invalidation of a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration. This can lead to permissions being granted long after the configuration was changed to no longer grant them.
Recommendations For Jenkins Role-based Authorization Strategy Plugin versions 3.0 and earlier, update to version 3.1 or newer to properly invalidate the cache on configuration changes.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2286
GHSA-25G4-P347-X748

Affected Products

Jenkins
Jenkins Role-Based Authorization Strategy Plugin