#VU46881 Permissions, Privileges, and Access Controls in Blue Ocean - CVE-2020-2255
Published: September 16, 2020 / Updated: September 22, 2020
Blue Ocean
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected plugin does not perform permission checks in several HTTP endpoints implementing connection tests. A remote user with Overall/Read permission can connect to an attacker-specified URL.