Jenkins Project Inheritance Plugin Vulnerability Exposes Job Configurations
CVE-2020-2197

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
3 June 2020

Summary

The Jenkins Project Inheritance Plugin prior to version 19.08.02 is affected by a vulnerability that permits unauthorized users to access and modify Inheritance Project job configurations in XML format. This weakness arises from the absence of proper permissions checks, allowing individuals without the necessary Job/ExtendedRead permissions to read sensitive job configuration data. This vulnerability could potentially be exploited to gain insights into project settings and configurations, leading to further security risks.

Affected Version(s)

Jenkins Project Inheritance Plugin <= 19.08.02

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.