CVE-2020-2272: Medium severity jenkins vulnerability
A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2272?
CVE-2020-2272 has a high severity rating due to the potential for unauthorized access through misconfigured permissions.
How do I fix CVE-2020-2272?
To fix CVE-2020-2272, upgrade to Jenkins Elastest Plugin version 1.2.2 or later where the permission checks have been implemented.
What kind of impact can CVE-2020-2272 have on my system?
CVE-2020-2272 can allow attackers with Overall/Read permission to connect to URLs using their own credentials, potentially leading to data breaches.
Which versions of Jenkins Elastest are affected by CVE-2020-2272?
Jenkins Elastest Plugin versions 1.2.1 and earlier are affected by CVE-2020-2272.
Who is at risk due to CVE-2020-2272?
Organizations using Jenkins Elastest Plugin version 1.2.1 or earlier are at risk if they have users with Overall/Read permissions.