PT-2020-15526 · Jenkins · Jenkins Shared Objects Plugin+1

Jeff Thompson

·

Published

2020-10-08

·

Updated

2023-11-03

·

CVE-2020-2296

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Shared Objects Plugin versions 0.44 and earlier
Description A cross-site request forgery (CSRF) issue allows attackers to configure shared objects. This can be exploited by attackers to perform unauthorized actions.
Recommendations For Jenkins Shared Objects Plugin versions 0.44 and earlier, update to a version later than 0.44 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's configuration options to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2020-2296
GHSA-2V9X-GPQ4-8GG2

Affected Products

Jenkins
Jenkins Shared Objects Plugin