CVE-2020-2260: Medium severity jenkins vulnerability
Published Sep 16, 2020
·Updated
A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
Affected Software
1 affected component
Jenkins Perfecto Jenkins<=1.17
Event History
Sep 16, 2020
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-2260?
CVE-2020-2260 is considered a medium severity vulnerability.
2
How do I fix CVE-2020-2260?
To fix CVE-2020-2260, update Jenkins Perfecto Plugin to version 1.18 or later.
3
What versions of Jenkins Perfecto Plugin are affected by CVE-2020-2260?
CVE-2020-2260 affects Jenkins Perfecto Plugin versions 1.17 and earlier.
4
Who can exploit CVE-2020-2260?
CVE-2020-2260 can be exploited by users with Overall/Read permission.
5
What type of vulnerability is CVE-2020-2260?
CVE-2020-2260 is a missing permission check vulnerability that allows unauthorized HTTP connections.