Cross-Site Request Forgery in Jenkins Database Plugin by Jenkins
CVE-2020-2241
8.8HIGH
What is CVE-2020-2241?
A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Database Plugin versions 1.6 and earlier. This flaw enables attackers to craft malicious requests that can connect to an external database server with credentials specified by the attacker. As a result, unauthorized access to sensitive database information or potential manipulation of data could occur. It is crucial for users to update their Jenkins Database Plugin to mitigate this risk and ensure secure operational integrity.
Affected Version(s)
Jenkins database Plugin <= 1.6