CVE-2020-2104: Medium severity Jenkins Jenkins vulnerability
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
Other sources
Jenkins includes a feature that shows a JVM memory usage chart for the Jenkins controller.
Access to the chart in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier requires no permissions beyond the general Overall/Read, allowing users who are not administrators to view JVM memory usage data.
Jenkins 2.219, LTS 2.204.2 now requires Overall/Administer permissions to view the JVM memory usage chart.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.219 - Upgrade
Upgrade
maven/org.jenkins-ci.main:jenkins-coreto a version that resolves this vulnerability.Fixed in 2.204.2
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2104?
CVE-2020-2104 has been rated as a medium severity vulnerability.
How do I fix CVE-2020-2104?
To fix CVE-2020-2104, upgrade Jenkins to version 2.219 or 2.204.2 or later.
Who is affected by CVE-2020-2104?
Users running Jenkins versions 2.218 and earlier or LTS 2.204.1 and earlier are affected by CVE-2020-2104.
What does CVE-2020-2104 allow?
CVE-2020-2104 allows users with Overall/Read access to view the JVM memory usage chart.
What is the impact of CVE-2020-2104?
The impact of CVE-2020-2104 is the potential exposure of sensitive memory usage information within Jenkins.