#VU27614 Improper Authorization in Amazon EC2 - CVE-2020-2188
Published: May 7, 2020
Amazon EC2
Jenkins
Description
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to the affected plugin performs improper permission checks when providing a list of applicable credentials IDs to allow users configuring the plugin to select the one to use. A remote authenticated attacker with Overall/Read permission can get a list of valid credentials IDs.