CVE-2020-2268

Description

A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.088

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-2267,CVE-2020-2268 are affected in Jenkins - mongodb 1.3Windows
Vulnerabilities CVE-2020-2267,CVE-2020-2268 are affected in Jenkins - mongodb for Linux 1.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234