CSRF Vulnerability in Jenkins Database Plugin by Jenkins
CVE-2020-2240
8.8HIGH
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 1 September 2020
What is CVE-2020-2240?
A CSRF vulnerability exists in the Jenkins Database Plugin, specifically affecting version 1.6 and earlier. This flaw could be exploited by malicious actors to perform unauthorized actions, enabling the execution of arbitrary SQL scripts on the Jenkins server. Attackers may craft a request that, when processed by an unsuspecting user, leverages their authenticated session to compromise data integrity and confidentiality. Users are urged to apply security patches promptly to mitigate this risk.
Affected Version(s)
Jenkins database Plugin <= 1.6