CVE-2020-2216: Medium severity zephyr for jira test management vulnerability
Published Jul 2, 2020
·Updated
A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified username and password.
Affected Software
2 affected components
maven/org.jenkins-ci.plugins:zephyr-for-jira-test-management<=1.5
Jenkins Zephyr For Jira Test Management Jenkins<=1.5
Event History
Jul 2, 2020
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
Description
May 24, 2022
Advisory Published
05:22 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-2216?
CVE-2020-2216 is rated as a medium severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2020-2216?
To fix CVE-2020-2216, update the Jenkins Zephyr for JIRA Test Management Plugin to version 1.6 or later.
3
Who is affected by CVE-2020-2216?
CVE-2020-2216 affects users of Jenkins Zephyr for JIRA Test Management Plugin version 1.5 and earlier.
4
Can CVE-2020-2216 be exploited remotely?
Yes, CVE-2020-2216 can be exploited remotely if an attacker has the Overall/Read permission.
5
What type of attack does CVE-2020-2216 facilitate?
CVE-2020-2216 allows an attacker to connect to a malicious HTTP server using provided credentials.