First published: Wed May 06 2020(Updated: )
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Amazon Ec2 | <=1.50.1 | |
maven/org.jenkins-ci.plugins:ec2 | <=1.50.1 | 1.50.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2186 is a cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier.
CVE-2020-2186 allows attackers to provision instances by exploiting a cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier.
CVE-2020-2186 has a severity rating of medium (4.3).
To fix CVE-2020-2186, update Jenkins Amazon EC2 Plugin to version 1.50.2 or later.
More information about CVE-2020-2186 can be found at the following links: - http://www.openwall.com/lists/oss-security/2020/05/06/3 - https://jenkins.io/security/advisory/2020-05-06/#SECURITY-1408