CVE-2020-2258: Medium severity jenkins health advisor vulnerability
Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to view an administrative configuration page.
Health Advisor by CloudBees Plugin 3.2.1 requires Overall/Administer to view its administrative configuration page.
Other sources
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2258?
CVE-2020-2258 is classified as a medium severity vulnerability.
How do I fix CVE-2020-2258?
To fix CVE-2020-2258, upgrade Health Advisor by CloudBees Plugin to version 3.2.1 or later.
What are the consequences of exploiting CVE-2020-2258?
Exploiting CVE-2020-2258 allows unauthorized users with Overall/Read permission to access sensitive administrative configuration information.
Which versions of the Health Advisor by CloudBees Plugin are affected by CVE-2020-2258?
CVE-2020-2258 affects versions of the Health Advisor by CloudBees Plugin up to and including 3.2.0.
Is CVE-2020-2258 a remote code execution vulnerability?
No, CVE-2020-2258 does not allow for remote code execution, but it does lead to unauthorized access to administrative configurations.