CVE-2020-2303: CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
Other sources
Jenkins Active Directory Plugin 2.19 and earlier does not require POST requests for multiple HTTP endpoints implementing connection and authentication tests, resulting in cross-site request forgery (CSRF) vulnerabilities.
This vulnerability allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
Active Directory Plugin 2.20 requires POST requests for the affected HTTP endpoints.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-2303?
CVE-2020-2303 is a cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier.
What is the severity of CVE-2020-2303?
The severity of CVE-2020-2303 is medium, with a CVSS score of 4.3.
How does CVE-2020-2303 affect Jenkins Active Directory Plugin?
CVE-2020-2303 affects Jenkins Active Directory Plugin 2.19 and earlier by allowing CSRF attacks through multiple HTTP endpoints.
How can an attacker exploit CVE-2020-2303?
An attacker can exploit CVE-2020-2303 by performing connection tests and connecting to unauthorized resources.
How can I mitigate CVE-2020-2303?
To mitigate CVE-2020-2303, upgrade Jenkins Active Directory Plugin to version 2.20 or later.