CVE-2020-2242: Medium severity jenkins vulnerability
Published Sep 1, 2020
·Updated
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:database<=1.6
1.7
Jenkins Database Jenkins<=1.6
Event History
Sep 1, 2020
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
May 24, 2022
Advisory Published
05:27 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-2242.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.'
3
What is the severity of CVE-2020-2242?
The severity of CVE-2020-2242 is medium with a CVSS score of 6.5.
4
What is the affected software?
The affected software is Jenkins Database Plugin version 1.6 and earlier.
5
How can I fix CVE-2020-2242?
To fix CVE-2020-2242, update Jenkins Database Plugin to a version beyond 1.6.