CVE-2020-2240: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.
Other sources
Database Plugin 1.6 and earlier does not require POST requests for the database console, resulting in a cross-site request forgery (CSRF) vulnerability.
This vulnerability allows attackers to execute arbitrary SQL scripts.
Database Plugin 1.7 removes the database console.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-2240?
CVE-2020-2240 refers to a cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier.
How does CVE-2020-2240 impact users?
CVE-2020-2240 allows attackers to execute arbitrary SQL scripts through a CSRF attack.
What is the severity of CVE-2020-2240?
CVE-2020-2240 is classified as high severity with a CVSS score of 8.8.
How can I fix CVE-2020-2240?
To fix CVE-2020-2240, users should update Jenkins database Plugin to version 1.7 or later.
Where can I find more information about CVE-2020-2240?
More information about CVE-2020-2240 can be found on the Openwall and Jenkins websites.