CVE-2020-2196

Description

Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.

Risk Information

Base Score
8.0
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.105

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-2196 are affected in Jenkins - selenium 3.141.59Windows
Vulnerabilities CVE-2020-2196 are affected in Jenkins - selenium for Linux 3.141.59Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234