First published: Mon Mar 09 2020(Updated: )
A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins P4 | <=1.10.10 | |
maven/org.jenkins-ci.plugins:p4 | <1.10.11 | 1.10.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2141 is classified as a moderate severity vulnerability due to its potential to allow unauthorized triggering of builds in Jenkins.
To fix CVE-2020-2141, upgrade the Jenkins P4 Plugin to version 1.10.11 or later.
CVE-2020-2141 affects Jenkins P4 Plugin versions 1.10.10 and earlier.
CVE-2020-2141 is a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2020-2141 can allow attackers to trigger builds or add labels in Perforce, leading to unauthorized actions.