Permissions, Privileges, and Access Controls in Blue Ocean - CVE-2020-2255
Published: September 16, 2020 / Updated: September 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected plugin does not perform permission checks in several HTTP endpoints implementing connection tests. A remote user with Overall/Read permission can connect to an attacker-specified URL.
Affected software
Red Hat OpenShift Container Platform
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2020-2255
jenkins-2-plugins (Red Hat package) - update to 3.11.1603460090-1.el7