CVE-2020-2306

Missing Authorization in maven/org.jenkins-ci.plugins/mercurial

Identifier

CVE-2020-2306

Package Slug

maven/org.jenkins-ci.plugins/mercurial

Vulnerability

Missing Authorization

Description

A missing permission check in Jenkins Mercurial Plugin allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.

Affected Versions

All versions up to 2.11

Solution

Unfortunately, there is no solution available yet.

Last Modified

2020-11-09

source