CVE-2020-2196

HIGH

Jenkins Selenium Plugin < 3.141.59 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/06/03/3
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/04/14/2

Scores

CVSS v3 8.0
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (2)
jenkins/selenium < 3.141.59
org.jenkins-ci.plugins/selenium 0Maven
Published Jun 03, 2020
Tracked Since Feb 18, 2026