CVE-2020-2302

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-2302
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-2302.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-2302
Aliases
Published
2020-11-04T15:15:11Z
Modified
2024-10-12T06:21:06.384081Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.

References

Affected packages

Git / github.com/jenkinsci/active-directory-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/active-directory-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

active-directory-1.*

active-directory-1.19
active-directory-1.20
active-directory-1.21
active-directory-1.22
active-directory-1.23
active-directory-1.24
active-directory-1.25
active-directory-1.26
active-directory-1.27
active-directory-1.28
active-directory-1.29
active-directory-1.30
active-directory-1.31
active-directory-1.32
active-directory-1.33
active-directory-1.34
active-directory-1.35
active-directory-1.36
active-directory-1.37
active-directory-1.38
active-directory-1.39
active-directory-1.40
active-directory-1.41
active-directory-1.42
active-directory-1.43
active-directory-1.44
active-directory-1.45
active-directory-1.46
active-directory-1.47
active-directory-1.48
active-directory-1.49

active-directory-2.*

active-directory-2.0
active-directory-2.1
active-directory-2.10
active-directory-2.11
active-directory-2.12
active-directory-2.13
active-directory-2.14
active-directory-2.15
active-directory-2.16
active-directory-2.17
active-directory-2.18
active-directory-2.19
active-directory-2.2
active-directory-2.3
active-directory-2.4
active-directory-2.5
active-directory-2.6
active-directory-2.7
active-directory-2.8
active-directory-2.9