Medium severity5.4NVD Advisory· Published Sep 23, 2020· Updated Jun 17, 2026
CVE-2020-2281
CVE-2020-2281
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.6wind.jenkins:lockable-resourcesMaven | < 2.9 | 2.9 |
Affected products
3- Range: unspecified
- cpe:2.3:a:jenkins:lockable_resources:*:*:*:*:*:jenkins:*:*Range: <=2.8
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/09/23/1nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-rvww-w62m-hch8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-2281ghsaADVISORY
- www.jenkins.io/security/advisory/2020-09-23/nvdVendor AdvisoryWEB
- github.com/jenkinsci/lockable-resources-plugin/commit/50ab82498f792775a761e6f4937607b240ecde67ghsaWEB
News mentions
1- Jenkins Security Advisory 2020-09-23Jenkins Security Advisories · Sep 23, 2020