CVE-2020-2196

Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:jenkins:selenium:*:*:*:*:*:jenkins:*:*

Information

Published : 2020-06-03 06:15

Updated : 2022-06-01 13:42


NVD link : CVE-2020-2196

Mitre link : CVE-2020-2196


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

jenkins

  • selenium