CVE-2020-2093Cross-Site Request Forgery in Project Jenkins Health Advisor BY Cloudbees Plugin

Severity
8.8HIGHNVD
EPSS
0.1%
top 74.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 24

Description

A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
CSRF vulnerability in Health Advisor by CloudBees Plugin2022-05-24
OSV
CSRF vulnerability in Health Advisor by CloudBees Plugin2022-05-24
CVEList
CVE-2020-2093: A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 32020-01-15

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2020-01-152020-01-15
CVE-2020-2093 — Cross-Site Request Forgery | cvebase