CVE-2020-2261: OS Command Injection
Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2261?
CVE-2020-2261 has a critical severity rating due to its potential to allow attackers to execute arbitrary commands on the Jenkins controller.
How do I fix CVE-2020-2261?
To fix CVE-2020-2261, upgrade the Jenkins Perfecto Plugin to version 1.18 or later.
Who is affected by CVE-2020-2261?
Any Jenkins instance using the Perfecto Plugin version 1.17 or earlier is affected by CVE-2020-2261.
What permissions are required to exploit CVE-2020-2261?
An attacker needs Job/Configure permission to exploit CVE-2020-2261 and execute arbitrary commands.
What are the potential consequences of CVE-2020-2261?
The potential consequences of CVE-2020-2261 include unauthorized access and control over the Jenkins controller, leading to data leaks or further attacks.