CVE-2020-2302: Medium severity jenkins active directory vulnerability
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
Other sources
Jenkins Active Directory Plugin 2.19 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to access the domain health check diagnostic page.
Jenkins Active Directory Plugin 2.20 requires Overall/Administer permission to access the domain health check diagnostic page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-2302?
CVE-2020-2302 is a vulnerability in Jenkins Active Directory Plugin 2.19 and earlier that allows attackers with Overall/Read permission to access the domain health check diagnostic page.
How severe is CVE-2020-2302?
CVE-2020-2302 has a severity rating of 4.3, which is considered medium.
How can I fix CVE-2020-2302?
To fix CVE-2020-2302, update to Jenkins Active Directory Plugin 2.20 or later, which requires Overall/Administer permission to access the affected endpoint.
Where can I find more information about CVE-2020-2302?
You can find more information about CVE-2020-2302 in the Jenkins security advisory, NVD database, and GitHub advisory pages.
What is the CWE ID for CVE-2020-2302?
The CWE ID for CVE-2020-2302 is 862.