Missing Permission Check in Jenkins Amazon EC2 Plugin Affects Security
CVE-2020-2188
4.3MEDIUM
Summary
A security vulnerability has been identified in the Amazon EC2 Plugin for Jenkins versions 1.50.1 and earlier, where a missing permission check in form-related methods allows users with Overall/Read access to enumerate the IDs of credentials stored in Jenkins. This flaw presents a significant risk as it could lead to unauthorized disclosure of sensitive information. Users are advised to review their permissions and upgrade their plugin versions to mitigate this risk.
Affected Version(s)
Jenkins Amazon EC2 Plugin <= 1.50.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved