CVE-2020-2235

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.08 % (33th)
0.08% Progress
Affected Products 1
Advisories 2

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.

Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2020-08-12 14:15:13
(4 years ago)
Updated Date
2023-10-25 18:16:38
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Pipeline Maven Integration for Jenkins 3.8.2 and prior versions cpe:2.3:a:jenkins:pipeline_maven_integration::*:*:*:*:jenkins <= 3.8.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...