Jenkins Project Inheritance Plugin Vulnerability Exposes Job Configurations
CVE-2020-2197
4.3MEDIUM
Summary
The Jenkins Project Inheritance Plugin prior to version 19.08.02 is affected by a vulnerability that permits unauthorized users to access and modify Inheritance Project job configurations in XML format. This weakness arises from the absence of proper permissions checks, allowing individuals without the necessary Job/ExtendedRead permissions to read sensitive job configuration data. This vulnerability could potentially be exploited to gain insights into project settings and configurations, leading to further security risks.
Affected Version(s)
Jenkins Project Inheritance Plugin <= 19.08.02
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved