#VU26018 Improper access control in Mac - CVE-2020-2148
Published: March 11, 2020
Mac
Jenkins
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected plugin does not perform permission checks on a method implementing form validation. A remote user with Overall/Read access can connect to an attacker-specified SSH host using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.