ZeroHour

CVE-2020-2196

CVSS 3.1
8.0 high
EPSS
<1%p59
Published
()
Modified
Description

Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.

Vendors
jenkins
Products
selenium
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.