First published: Wed Jun 03 2020(Updated: )
Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Self-organizing Swarm Modules | <=3.20 | |
maven/org.jenkins-ci.plugins:swarm | <3.21 | 3.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2191 is considered a critical vulnerability due to improper authentication that allows unauthorized modifications.
To fix CVE-2020-2191, upgrade the Jenkins Self-Organizing Swarm Plug-in Modules Plugin to version 3.21 or later.
Exploiting CVE-2020-2191 can allow attackers to add or remove agent labels without proper authorization, potentially leading to unauthorized access.
CVE-2020-2191 affects versions 3.20 and earlier of the Jenkins Self-Organizing Swarm Plug-in Modules Plugin.
There are no specific temporary workarounds for CVE-2020-2191, the best approach is to update to a patched version.