Cross-Site Request Forgery Vulnerability in Jenkins Self-Organizing Swarm Plugin
CVE-2020-2192
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 3 June 2020
What is CVE-2020-2192?
A cross-site request forgery vulnerability exists in the Jenkins Self-Organizing Swarm Plug-in Modules Plugin version 3.20 and earlier. This flaw allows attackers to manipulate agent labels on Jenkins instances, potentially leading to unauthorized control over build agents and compromising the integrity of the continuous integration environment. To mitigate this risk, users are advised to upgrade to the latest version of the plugin and implement security best practices.
Affected Version(s)
Jenkins Self-Organizing Swarm Plug-in Modules Plugin <= 3.20