CVE-2020-2320: Critical severity jenkins installation manager tool vulnerability
Published Dec 3, 2020
·Updated
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
Affected Software
2 affected componentsFixes available
Jenkins Installation Manager Tool Jenkins<=2.1.3
maven/io.jenkins.plugin-management:plugin-management-parent-pom<2.2.0
2.2.0
Event History
Dec 3, 2020
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
Description
May 24, 2022
Advisory Published
05:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-2320?
CVE-2020-2320 is classified as a medium severity vulnerability due to its impact on the integrity of plugin downloads.
2
How do I fix CVE-2020-2320?
To fix CVE-2020-2320, upgrade Jenkins Plugin Installation Manager Tool to version 2.2.0 or later.
3
What is the impact of CVE-2020-2320?
The impact of CVE-2020-2320 allows an attacker to potentially compromise the integrity of plugin installations by manipulating plugin downloads.
4
Which versions are affected by CVE-2020-2320?
CVE-2020-2320 affects all versions of Jenkins Plugin Installation Manager Tool up to and including 2.1.3.
5
Is CVE-2020-2320 present in Docker images of Jenkins?
Yes, CVE-2020-2320 is present in Jenkins project Docker images that include the affected versions of the Plugin Installation Manager Tool.