CVE-2020-2285
published 2020-09-23CVE-2020-2285: A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of…
medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | email_extension_plugin | — | — |
| jenkins | implied_labels_plugin | — | — |
| jenkins | liquibase_changesets_evaluated_by_the_plugin | — | — |
| jenkins | liquibase_runner | <= 1.4.7 | — |
| jenkins | liquibase_runner_plugin | — | — |
| jenkins | lockable_resources_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | warnings_next_generation_plugin | — | — |
| jenkins | warnings_plugin | — | — |
| jenkins_project | jenkins_liquibase_runner_plugin | unspecified – 1.4.7 | — |