CSRF Vulnerability in Jenkins Database Plugin by Jenkins
CVE-2020-2240
8.8HIGH
Summary
A CSRF vulnerability exists in the Jenkins Database Plugin, specifically affecting version 1.6 and earlier. This flaw could be exploited by malicious actors to perform unauthorized actions, enabling the execution of arbitrary SQL scripts on the Jenkins server. Attackers may craft a request that, when processed by an unsuspecting user, leverages their authenticated session to compromise data integrity and confidentiality. Users are urged to apply security patches promptly to mitigate this risk.
Affected Version(s)
Jenkins database Plugin <= 1.6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved