Missing Permission Check in Jenkins P4 Plugin by Jenkins
CVE-2020-2142
4.3MEDIUM
What is CVE-2020-2142?
The Jenkins P4 Plugin, specifically in versions up to and including 1.10.10, is affected by a vulnerability that allows users with Overall/Read permissions to trigger builds without proper authorization. This poses a significant security risk as unauthorized individuals could execute builds, potentially leading to the manipulation of code or the introduction of malware into the build pipeline. It is critical for users to apply patches and effectively manage permissions to safeguard their Jenkins environments.
Affected Version(s)
Jenkins P4 Plugin <= 1.10.10