CVE-2020-2310

Missing Authorization in maven/org.jenkins-ci.plugins/ansible

Identifier

CVE-2020-2310

Package Slug

maven/org.jenkins-ci.plugins/ansible

Vulnerability

Missing Authorization

Description

Missing permission checks in Jenkins Ansible Plugin allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Affected Versions

All versions up to 1.0

Solution

Upgrade to version 1.1 or above.

Last Modified

2020-11-13

source