Missing Permission Check in Jenkins Amazon EC2 Plugin Affects Security
CVE-2020-2188

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
6 May 2020

Summary

A security vulnerability has been identified in the Amazon EC2 Plugin for Jenkins versions 1.50.1 and earlier, where a missing permission check in form-related methods allows users with Overall/Read access to enumerate the IDs of credentials stored in Jenkins. This flaw presents a significant risk as it could lead to unauthorized disclosure of sensitive information. Users are advised to review their permissions and upgrade their plugin versions to mitigate this risk.

Affected Version(s)

Jenkins Amazon EC2 Plugin <= 1.50.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.