CVE-2020-2192

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-2192
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-2192.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-2192
Aliases
Published
2020-06-03T13:15:10Z
Modified
2024-09-03T03:21:39.297889Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels.

References

Affected packages

Git / github.com/jenkinsci/swarm-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/swarm-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

swarm-plugin-1.*

swarm-plugin-1.10
swarm-plugin-1.11
swarm-plugin-1.12
swarm-plugin-1.13
swarm-plugin-1.14
swarm-plugin-1.15
swarm-plugin-1.16
swarm-plugin-1.17
swarm-plugin-1.18
swarm-plugin-1.19
swarm-plugin-1.20
swarm-plugin-1.21
swarm-plugin-1.22
swarm-plugin-1.23
swarm-plugin-1.24
swarm-plugin-1.25
swarm-plugin-1.26
swarm-plugin-1.5
swarm-plugin-1.6
swarm-plugin-1.7
swarm-plugin-1.8
swarm-plugin-1.9

swarm-plugin-2.*

swarm-plugin-2.0
swarm-plugin-2.1
swarm-plugin-2.2
swarm-plugin-2.3

swarm-plugin-3.*

swarm-plugin-3.0
swarm-plugin-3.1
swarm-plugin-3.10
swarm-plugin-3.11
swarm-plugin-3.12
swarm-plugin-3.13
swarm-plugin-3.14
swarm-plugin-3.15
swarm-plugin-3.16
swarm-plugin-3.17
swarm-plugin-3.18
swarm-plugin-3.19
swarm-plugin-3.2
swarm-plugin-3.20
swarm-plugin-3.3
swarm-plugin-3.4
swarm-plugin-3.5
swarm-plugin-3.6
swarm-plugin-3.7
swarm-plugin-3.8
swarm-plugin-3.9