Jenkins Chaos Monkey Plugin Vulnerability Allowing Unrestricted Access
CVE-2020-2322
7.5HIGH
What is CVE-2020-2322?
The Jenkins Chaos Monkey Plugin version 0.3 and earlier is vulnerable due to insufficient permission checks across multiple HTTP endpoints. This flaw allows attackers with Overall/Read permission to exploit the plugin's functionality, generating excessive load and potentially leading to memory leaks. Users should promptly update to the latest version to mitigate these security risks.
Affected Version(s)
Jenkins Chaos Monkey Plugin <= 0.3
Jenkins Chaos Monkey Plugin 0.4.1