CSRF Vulnerability in Jenkins Database Plugin by Jenkins
CVE-2020-2240

8.8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
1 September 2020

Summary

A CSRF vulnerability exists in the Jenkins Database Plugin, specifically affecting version 1.6 and earlier. This flaw could be exploited by malicious actors to perform unauthorized actions, enabling the execution of arbitrary SQL scripts on the Jenkins server. Attackers may craft a request that, when processed by an unsuspecting user, leverages their authenticated session to compromise data integrity and confidentiality. Users are urged to apply security patches promptly to mitigate this risk.

Affected Version(s)

Jenkins database Plugin <= 1.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.