CVE-2020-2103
Jenkins Diagnostic page exposed session cookies
Record summary
CVE-2020-2103 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | Through 2.218 | affected | |
| Through LTS 2.204.1 | affected | ||
org.jenkins-ci.main:jenkins-coreBrowse Maven / org.jenkins-ci.main:jenkins-core | GitHub Advisory | 2.205 to < 2.219 · Fixed in 2.219 | affected |
| Before 2.204.2 · Fixed in 2.204.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMJenkins <=2.218 - Information DisclosureCVSS 5.4
Jenkins through 2.218, LTS 2.204.1 and earlier, is susceptible to information disclosure. An attacker can access exposed session identifiers on a user detail object in the whoAmI diagnostic page and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the Jenkins server.
Remediation
Upgrade Jenkins to a version higher than 2.218 to mitigate the vulnerability.
Source: ProjectDiscovery