CVE-2020-2261

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/09/2020
Last modified:
25/10/2023

Description

Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:perfecto:*:*:*:*:*:jenkins:*:* 1.17 (including)