CVE-2020-2200: Command Injection
Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the play command on the Jenkins master for a form validation endpoint, resulting in an OS command injection vulnerability exploitable by users able to store such a file on the Jenkins master.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2200?
CVE-2020-2200 is categorized as a medium severity vulnerability.
How do I fix CVE-2020-2200?
To fix CVE-2020-2200, upgrade the Jenkins Play Framework Plugin to version 1.0.3 or later.
What are the potential consequences of exploiting CVE-2020-2200?
Exploiting CVE-2020-2200 can lead to OS command injection, allowing an attacker to execute arbitrary commands on the Jenkins master.
Which versions of Jenkins Play Framework are affected by CVE-2020-2200?
CVE-2020-2200 affects Jenkins Play Framework Plugin versions 1.0.2 and earlier.
Who is vulnerable to CVE-2020-2200?
Users who have the Jenkins Play Framework Plugin installed on their Jenkins master are vulnerable to CVE-2020-2200.