Back to search
CVE-2020-2286
Published: Oct 8, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration.
| Vendor | Product | Versions |
|---|---|---|
Jenkins project | Jenkins Role-based Authorization Strategy Plugin | affected 2.12 - < unspecifiedaffected unspecified - <= 3.0 |
References
https://www.jenkins.io/security/advisory/2020-10-08/#SECURITY-1767
x_refsource_CONFIRM
[oss-security] 20201008 Multiple vulnerabilities in Jenkins plugins
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now