CVE-2020-2215
published 2020-07-02CVE-2020-2215: A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.68%
48.1th percentile
A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | cd_plugin | — | — |
| jenkins | compatibility_action_storage_plugin | — | — |
| jenkins | fortify_on_demand_plugin | — | — |
| jenkins | github_coverage_reporter_plugin | — | — |
| jenkins | hp_alm_quality_center_plugin | — | — |
| jenkins | ids_in_fortify_on_demand_plugin | — | — |
| jenkins | ids_to_allow_users_configuring_the_plugin | — | — |
| jenkins | link_column_plugin | — | — |
| jenkins | slack_upload_plugin | — | — |
| jenkins | sonargraph_integration_plugin | — | — |
| jenkins | stash_branch_parameter_plugin | — | — |
| jenkins | testcomplete_support_plugin | — | — |
| jenkins | vncrecorder_plugin | — | — |
| jenkins | vncviewer_plugin | — | — |
| jenkins | zap_pipeline_plugin | — | — |
| jenkins | zephyr_for_jira_test_management | <= 1.5 | — |
| jenkins | zephyr_for_jira_test_management_plugin | — | — |
| jenkins_project | jenkins_zephyr_for_jira_test_management_plugin | unspecified – 1.5 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
cisa7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0069 [HIGH] CWE-787 Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Vulnerability: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Affected: MediaTek Multiple Chipsets
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0069
Remediation Due Date: 2022-05-03
CISA
Android Kernel Out-of-Bounds Write Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-0041 [HIGH] CWE-20 Android Kernel Out-of-Bounds Write Vulnerability
Vulnerability: Android Kernel Out-of-Bounds Write Vulnerability
Affected: Android Android Kernel
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0041
Remediation Due Date: 2022-05-03
CISA
Android Kernel Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2019-2215 [HIGH] CWE-416 Android Kernel Use-After-Free Vulnerability
Vulnerability: Android Kernel Use-After-Free Vulnerability
Affected: Android Android Kernel
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-2215
Remediation Due Date: 2022-05-03
Jenkins
Jenkins Security Advisory 2020-07-02
vendor_jenkins·2020-07-02·CVSS 5.4
CVE-2020-2201 [MEDIUM] Jenkins Security Advisory 2020-07-02
Title: Jenkins Security Advisory 2020-07-02
Jenkins Security Advisory 2020-07-02
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Compatibility Action Storage
Plugin
Fortify on Demand
Plugin
Fortify on Demand
Plugin
GitHub Coverage Reporter
Plugin
HP ALM Quality Center
Plugin
ElasticBox Jenkins Kub
OSV
CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
osv·2022-05-24
CVE-2020-2215 [MEDIUM] CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.
GHSA
CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
ghsa·2022-05-24
CVE-2020-2215 [MEDIUM] CWE-352 CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
CSRF vulnerability in Jenkins Zephyr for JIRA Test Management Plugin
A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.
No detection rules found.
No public exploits indexed.
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobilgeräte
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen Jan 06, 2020 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known ac
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobile
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen 2020/01/06 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known active at
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Dispositivos móviles
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen Jan 06, 2020 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first
Trendmicro
First Binder Exploit Linked to SideWinder APT Group
blogs_trendmicro·2020-01-06·CVSS 7.8
CVE-2019-2215 [HIGH] First Binder Exploit Linked to SideWinder APT Group
Mobile
## First Binder Exploit Linked to SideWinder APT Group
We found malicious apps that work together to compromise devices and collect user data. One of the apps, called Camero, exploits CVE-2019-2215, a flaw that exists in Binder. This is the first instance in the wild that exploits said UAF vulnerability.
By: Ecular Xu, Joseph C Chen Jan 06, 2020 Read time: ( words)
Save to Folio
Updated January 8, 2020 5PM EST with a video showing the exploit of CVE-2019-2215.
We found three malicious apps in the Google Play Store that work together to compromise a victim’s device and collect user information. One of these apps, called Camero, exploits CVE-2019-2215 , a vulnerability that exists in Binder (the main Inter-Process Communication system in Android). This is the first known active
2020-07-02
Published