CVE-2020-2296 describes a Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin versions 0.44 and earlier, allowing unauthenticated attackers to configure shared objects. With a CVSS score of 4.3 (Medium), this vulnerability has a low impact on integrity and requires user interaction, but is easily exploitable over the network. There is currently no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.44CPE matchmatch criteria | cpe:2.3:a:jenkins:shared_objects:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.