Record summary

CVE-2020-2103 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListThrough 2.218affected
Through LTS 2.204.1affected

org.jenkins-ci.main:jenkins-core

Browse Maven / org.jenkins-ci.main:jenkins-core
GitHub Advisory2.205 to < 2.219 · Fixed in 2.219affected
Before 2.204.2 · Fixed in 2.204.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMJenkins <=2.218 - Information DisclosureCVSS 5.4

Jenkins through 2.218, LTS 2.204.1 and earlier, is susceptible to information disclosure. An attacker can access exposed session identifiers on a user detail object in the whoAmI diagnostic page and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the Jenkins server.

Remediation

Upgrade Jenkins to a version higher than 2.218 to mitigate the vulnerability.

WeaknessesCWE-200
Authorsc-sh0
Template tagscvecve2020jenkinsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Shodan: http.favicon.hash:81586312
Shodan: cpe:"cpe:2.3:a:jenkins:jenkins"
Shodan: product:"jenkins"
FOFA: icon_hash=81586312

Source: ProjectDiscovery

References

9