Privilege Escalation Vulnerability in Jenkins Gitlab Authentication Plugin
CVE-2020-2228
8.8HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 15 July 2020
Summary
The Jenkins Gitlab Authentication Plugin, versions 1.5 and earlier, does not adequately enforce group authorization checks. This oversight can potentially allow unauthorized users to escalate their privileges, leading to unauthorized access and control over Jenkins resources. It is crucial for users to upgrade to the latest version of the plugin to mitigate this vulnerability and secure their Jenkins environment.
Affected Version(s)
Jenkins Gitlab Authentication Plugin <= 1.5
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved