CVE-2020-2310: Medium severity jenkins vulnerability
Jenkins Ansible Plugin 1.0 and earlier does not perform permission checks in methods implementing form validation.
This allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.
An enumeration of credentials IDs in Ansible Plugin 1.1 requires the appropriate permissions.
Other sources
Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2310?
CVE-2020-2310 is classified as a High severity vulnerability due to its potential to expose sensitive credential information.
How do I fix CVE-2020-2310?
To fix CVE-2020-2310, upgrade the Jenkins Ansible Plugin to version 1.1 or later.
What types of permissions are exploited in CVE-2020-2310?
CVE-2020-2310 can be exploited by attackers with Overall/Read permission in Jenkins.
What data is exposed due to CVE-2020-2310?
CVE-2020-2310 allows attackers to enumerate IDs of stored credentials in Jenkins.
In which versions of Jenkins Ansible Plugin does CVE-2020-2310 exist?
CVE-2020-2310 exists in Jenkins Ansible Plugin versions 1.0 and earlier.