CVE-2020-2322 – io.jenkins.plugins:chaos-monkey
Package
Manager: maven
Name: io.jenkins.plugins:chaos-monkey
Vulnerable Version: >=0 <0.4
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00349 pctl0.56656
Details
Missing permission checks in Jenkins Chaos Monkey Plugin Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints. This allows attackers with Overall/Read permission to generate load and to generate memory leaks. Jenkins Chaos Monkey Plugin 0.4 requires Overall/Administer permission to generate load and to generate memory leaks.
Metadata
Created: 2022-05-24T17:35:09Z
Modified: 2023-10-27T13:16:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mr75-899x-qcxq/GHSA-mr75-899x-qcxq.json
CWE IDs: ["CWE-401", "CWE-862"]
Alternative ID: GHSA-mr75-899x-qcxq
Finding: F039
Auto approve: 1