CVE-2020-2228Incorrect Authorization in Project Jenkins Gitlab Authentication Plugin

Severity
8.8HIGHNVD
EPSS
0.1%
top 65.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

4
OSV
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin2022-05-24
GHSA
Improper authorization of users and groups with the same base name in Jenkins GitLab Authentication Plugin2022-05-24
CVEList
CVE-2020-2228: Jenkins Gitlab Authentication Plugin 12020-07-15
OSV
cups vulnerabilities2020-04-27

💥Exploits & PoCs

1
Exploit-DB
NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection2020-05-28

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2020-07-152020-07-15
GitLab
CVE-2020-2228: Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnera2020-07-15
CVE-2020-2228 — Incorrect Authorization | cvebase