API Permissions Issue in Jenkins Self-Organizing Swarm Plug-in Modules
CVE-2020-2191
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 3 June 2020
What is CVE-2020-2191?
The Jenkins Self-Organizing Swarm Plug-in Modules Plugin versions 3.20 and earlier possess a significant API permissions issue. This vulnerability allows unauthorized users to add or remove agent labels without proper permissions, potentially leading to improper access control and manipulation of the Jenkins environment. As a result, administrators should take immediate action to secure their installations by updating to the latest version and reviewing user permissions thoroughly.
Affected Version(s)
Jenkins Self-Organizing Swarm Plug-in Modules Plugin <= 3.20