Jenkins Project Inheritance Plugin Vulnerability Exposes Job Configurations
CVE-2020-2197
What is CVE-2020-2197?
The Jenkins Project Inheritance Plugin prior to version 19.08.02 is affected by a vulnerability that permits unauthorized users to access and modify Inheritance Project job configurations in XML format. This weakness arises from the absence of proper permissions checks, allowing individuals without the necessary Job/ExtendedRead permissions to read sensitive job configuration data. This vulnerability could potentially be exploited to gain insights into project settings and configurations, leading to further security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Project Inheritance Plugin <= 19.08.02
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved