Medium severity4.3NVD Advisory· Published Sep 23, 2020· Updated Jun 17, 2026
CVE-2020-2282
CVE-2020-2282
Description
Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to configure the plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:implied-labelsMaven | < 0.7 | 0.7 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2020/09/23/1nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-5hw2-327v-vvr6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-2282ghsaADVISORY
- www.jenkins.io/security/advisory/2020-09-23/nvdVendor AdvisoryWEB
- github.com/jenkinsci/implied-labels-plugin/commit/9a5d38f8056a830ef075f379fa1b489c08f7000fghsaWEB
News mentions
1- Jenkins Security Advisory 2020-09-23Jenkins Security Advisories · Sep 23, 2020