Cross-Site Request Forgery in Jenkins Database Plugin by Jenkins
CVE-2020-2241

8.8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
1 September 2020

Summary

A cross-site request forgery (CSRF) vulnerability exists in the Jenkins Database Plugin versions 1.6 and earlier. This flaw enables attackers to craft malicious requests that can connect to an external database server with credentials specified by the attacker. As a result, unauthorized access to sensitive database information or potential manipulation of data could occur. It is crucial for users to update their Jenkins Database Plugin to mitigate this risk and ensure secure operational integrity.

Affected Version(s)

Jenkins database Plugin <= 1.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.