Cross-Site Request Forgery Vulnerability in Jenkins Health Advisor by CloudBees
CVE-2020-2093
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 January 2020
What is CVE-2020-2093?
The Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier is susceptible to a cross-site request forgery (CSRF) vulnerability, allowing attackers to send emails with pre-defined content to any recipient specified by the attacker. This flaw exploits user interactions and can facilitate unauthorized communications, potentially leading to further compromise.
Affected Version(s)
Jenkins Health Advisor by CloudBees Plugin <= 3.0