Medium severity4.3NVD Advisory· Published Sep 16, 2020· Updated Jun 17, 2026
CVE-2020-2258
CVE-2020-2258
Description
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:cloudbees-jenkins-advisorMaven | < 3.2.1 | 3.2.1 |
Affected products
3- Range: unspecified
- cpe:2.3:a:jenkins:health_advisor_by_cloudbees:*:*:*:*:*:jenkins:*:*Range: <=3.2.0
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/09/16/3nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-c445-xm3f-hmfhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-2258ghsaADVISORY
- www.jenkins.io/security/advisory/2020-09-16/nvdVendor AdvisoryWEB
- github.com/jenkinsci/cloudbees-jenkins-advisor-plugin/commit/90f693a4b9fc60292463ecd7aa06c2c53d9dea30ghsaWEB
News mentions
1- Jenkins Security Advisory 2020-09-16Jenkins Security Advisories · Sep 16, 2020