CVE-2020-2276

HIGH8.8EPSS 0.67%

System command execution vulnerability in Selection tasks Jenkins Plugin

Published: 5/24/2022Modified: 11/8/2023
Also known as:GHSA-79h8-7735-v3f9

Description

Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure permission to execute an arbitrary system command on the Jenkins controller as the OS user that the Jenkins process is running as.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (4)