CVE-2020-2228
published 2020-07-15CVE-2020-2228: Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.43%
70.1th percentile
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11 | 2.1.3-4ubuntu0.11 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.8 | 2.2.7-1ubuntu2.8 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.1 | 2.3.1-9ubuntu1.1 |
| gitlab | gitlab | — | — |
| jenkins | deployer_framework_plugin | — | — |
| jenkins | gitlab_authentication | <= 1.5 | — |
| jenkins | gitlab_authentication_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | matrix_authorization_strategy_plugin | — | — |
| jenkins | matrix_project_plugin | — | — |
| jenkins_project | jenkins_gitlab_authentication_plugin | unspecified – 1.5 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
osv·2022-05-24
CVE-2020-2228 [HIGH] Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
GitLab Authentication Plugin 1.5 and earlier does not differentiate between user names and hierarchical group names when performing authorization. This allows an attacker with permissions to create groups in GitLab to gain the privileges granted to another user or group.
GitLab Authentication Plugin 1.6 performs user name and group name authorization checks using the appropriate GitLab APIs.
GHSA
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
ghsa·2022-05-24
CVE-2020-2228 [HIGH] CWE-863 Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin
GitLab Authentication Plugin 1.5 and earlier does not differentiate between user names and hierarchical group names when performing authorization. This allows an attacker with permissions to create groups in GitLab to gain the privileges granted to another user or group.
GitLab Authentication Plugin 1.6 performs user name and group name authorization checks using the appropriate GitLab APIs.
OSV
cups vulnerabilities
osv·2020-04-27·CVSS 5.5
CVE-2019-2228 cups vulnerabilities
cups vulnerabilities
It was discovered that CUPS incorrectly handled certain language values. A
local attacker could possibly use this issue to cause CUPS to crash,
leading to a denial of service, or possibly obtain sensitive information.
This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
19.10. (CVE-2019-2228)
Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed
ppd files. A local attacker could possibly use this issue to execute
arbitrary code. (CVE-2020-3898)
Jenkins
Jenkins Security Advisory 2020-07-15
vendor_jenkins·2020-07-15·CVSS 5.4
CVE-2020-2220 [MEDIUM] Jenkins Security Advisory 2020-07-15
Title: Jenkins Security Advisory 2020-07-15
Jenkins Security Advisory 2020-07-15
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Deployer Framework
Plugin
GitLab Authentication
Plugin
Matrix Authorization Strategy
Plugin
Matrix Project
Plugin
Descriptions
Stored XSS vulnerability in jo
GitLab
CVE-2020-2228: Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnera
vendor_gitlab·2020-07-15·CVSS 8.8
CVE-2020-2228 [HIGH] CWE-863 CVE-2020-2228: Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnera
CVE-2020-2228: Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
No detection rules found.
No writeups or analysis indexed.
2020-07-15
Published