PT-2020-15536 · Jenkins · Jenkins Mercurial Plugin+1

Published

2020-11-04

·

Updated

2023-10-25

·

CVE-2020-2306

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Mercurial Plugin versions 2.11 and earlier Jenkins Mercurial Plugin versions prior to 2.12
Description A missing permission check in the Jenkins Mercurial Plugin allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations. This issue is related to an HTTP endpoint that does not perform a permission check, enabling attackers to access sensitive information.
Recommendations For Jenkins Mercurial Plugin versions 2.11 and earlier, update to version 2.12 or later to resolve the issue. For Jenkins Mercurial Plugin versions prior to 2.12, update to version 2.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP endpoint related to Mercurial installations to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2306
GHSA-VRRC-3WWH-FRGX
RHSA-2021:0034
RHSA-2021:0038
RHSA-2021:0637

Affected Products

Jenkins
Jenkins Mercurial Plugin