
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-2216 is a security vulnerability discovered in the Jenkins Zephyr for JIRA Test Management Plugin version 1.5 and earlier. The vulnerability was disclosed on July 2, 2020, and is characterized by a missing permission check in a method implementing form validation (Jenkins Advisory, OSS Security).
The vulnerability stems from a missing permission check in a form validation method. This security flaw allows users with Overall/Read access to Jenkins to connect to an attacker-specified host using attacker-specified username and password. The vulnerability has been assigned a Medium severity CVSS rating (Jenkins Advisory).
The vulnerability enables users with basic Overall/Read access to potentially connect to unauthorized systems using arbitrary credentials, which could lead to unauthorized access and potential data exposure (Jenkins Advisory).
The vulnerability can be exploited by users who have Overall/Read access to Jenkins. The exploitation requires the ability to access form validation functionality in the Zephyr for JIRA Test Management Plugin (Jenkins Advisory).
As of the advisory publication date on July 2, 2020, no fix was available for this vulnerability in the Zephyr for JIRA Test Management Plugin. Organizations using version 1.5 or earlier of the plugin should assess their risk and consider implementing additional access controls to limit Overall/Read access to trusted users (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."