CVE-2020-2148 is a missing permission check vulnerability in Jenkins Mac Plugin versions 1.1.0 and earlier. It allows authenticated attackers with Overall/Read permission to connect to an arbitrary SSH server using attacker-provided credentials. This vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a low attack complexity and impact, primarily affecting integrity. There is no known exploit code available, nor is there evidence of active exploitation, Metasploit modules, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.0CPE matchmatch criteria | cpe:2.3:a:jenkins:mac:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.