Arbitrary Command Execution in Jenkins Selection Tasks Plugin by CloudBees
CVE-2020-2276
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 16 September 2020
What is CVE-2020-2276?
The Jenkins Selection Tasks Plugin, prior to version 1.0, has a vulnerability that allows an attacker with Job/Configure permission on the Jenkins controller to execute arbitrary system commands. This occurs because the plugin improperly executes user-specified programs, which can compromise the security of the Jenkins environment by executing malicious commands with the same privileges as the Jenkins process.
Affected Version(s)
Jenkins Selection tasks Plugin <= 1.0