CVE-2020-2159 is a critical vulnerability affecting Jenkins CryptoMove Plugin versions 0.1.33 and earlier. It allows authenticated attackers with Job/Configure permissions to execute arbitrary operating system commands on the Jenkins master, leveraging the privileges of the Jenkins service account. With a CVSS score of 8.8 (High), this flaw presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, the potential for a complete system compromise remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.1.33CPE matchmatch criteria | cpe:2.3:a:jenkins:cryptomove:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.