CVE-2020-2299
Vulnerability Scoring
Attack Complexity Details
- Attack Complexity: Low Impact
- Attack Vector: NETWORK
- Privileges Required: None
- Scope: UNCHANGED
- User Interaction: NONE
CIA Impact Definition
- Confidentiality: HIGH IMPACT
- Integrity: HIGH IMPACT
- Availability: HIGH IMPACT
CVE-2020-2299 Vulnerability Summary
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
Access Complexity Graph for CVE-2020-2299
Impact Analysis for CVE-2020-2299
CVE-2020-2299: Detailed Information and External References
EPSS
0.00211
EPSS %
0.59162
References
0.00211
- http://www.openwall.com/lists/oss-security/2020/11/04/6
- https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2117
CWE
Unknown
Vulnerable Configurations
-
cpe:2.3:a:jenkins:active_directory:1.0:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.0:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.1:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.1:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.2:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.2:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.3:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.3:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.4:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.4:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.5:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.5:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.6:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.6:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.7:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.7:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.8:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.8:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.9:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.9:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.10:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.10:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.11:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.11:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.12:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.12:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.13:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.13:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.14:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.14:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.15:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.15:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.16:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.16:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.17:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.17:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.18:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.18:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.19:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.19:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.20:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.20:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.21:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.21:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.22:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.22:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.23:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.23:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.24:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.24:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.25:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.25:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.26:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.26:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.27:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.27:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.28:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.28:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.29:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.29:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.30:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.30:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.31:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.31:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.32:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.32:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.33:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.33:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.34:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.34:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.35:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.35:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.36:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.36:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.37:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.37:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.38:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.38:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.39:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.39:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.40:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.40:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.41:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.41:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.42:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.42:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.43:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.43:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.44:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.44:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.45:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.45:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.46:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.46:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.47:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.47:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.48:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.48:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:1.49:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:1.49:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.0:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.0:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.1:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.1:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.2:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.2:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.3:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.3:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.4:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.4:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.5:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.5:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.6:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.6:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.7:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.7:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.8:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.8:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.9:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.9:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.10:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.10:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.11:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.11:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.12:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.12:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.13:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.13:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.14:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.14:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.15:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.15:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.16:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.16:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.16.1:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.16.1:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.17:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.17:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.18:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.18:*:*:*:*:jenkins:*:*
-
cpe:2.3:a:jenkins:active_directory:2.19:*:*:*:*:jenkins:*:*
cpe:2.3:a:jenkins:active_directory:2.19:*:*:*:*:jenkins:*:*
CVSS3 Source
nvd@nist.gov
CVSS3 Type
Primary
CVSS3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Protect Your Infrastructure: Combat Critical CVE Threats
Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.