CVE-2020-2215: CSRF
Published Jul 2, 2020
·Updated
A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.
Affected Software
1 affected component
Jenkins Zephyr For Jira Test Management Jenkins<=1.5
Event History
Jul 2, 2020
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-2215?
CVE-2020-2215 is considered a medium severity vulnerability due to its potential for exploitation via cross-site request forgery.
2
How do I fix CVE-2020-2215?
To fix CVE-2020-2215, upgrade to version 1.6 or later of the Jenkins Zephyr for JIRA Test Management Plugin.
3
What type of vulnerability is CVE-2020-2215?
CVE-2020-2215 is a cross-site request forgery (CSRF) vulnerability.
4
Who is affected by CVE-2020-2215?
CVE-2020-2215 affects anyone using Jenkins Zephyr for JIRA Test Management Plugin version 1.5 and earlier.
5
What could an attacker do with CVE-2020-2215?
An attacker exploiting CVE-2020-2215 could connect to an attacker-specified HTTP server using their own credentials.