CVE-2020-2281
CSRF vulnerability in Jenkins Lockable Resources Plugin
5.4
MEDIUM
CVSS 3.1
EPSS 0.12%
Description
Lockable Resources Plugin 2.8 and earlier does not require POST requests for several HTTP endpoints, resulting in a cross-site request forgery (CSRF) vulnerability. This vulnerability allows attackers to reserve, unreserve, unlock, and reset resources. Lockable Resources Plugin 2.9 requires POST requests for the affected HTTP endpoints.
How to fix CVE-2020-2281
To remediate CVE-2020-2281, upgrade the affected package to a fixed version below.
- —upgrade to 2.9 or later
Is CVE-2020-2281 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |