#VU46883 Permissions, Privileges, and Access Controls in Health Advisor by CloudBees - CVE-2020-2258
Published: September 16, 2020 / Updated: September 22, 2020
Health Advisor by CloudBees
Jenkins
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected plugin does not correctly perform a permission check in an HTTP endpoint. A remote authenticated attacker with Overall/Read permission can view an administrative configuration page.