-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit patching CVE-2020-2091 adds both @RequirePOST annotations and Jenkins.ADMINISTER permission checks to these form validation methods. The vulnerability description explicitly states that pre-patch versions allowed users with Overall/Read access to execute these methods via GET requests without authorization. The diff shows these security measures were absent in vulnerable versions, confirming these functions as the attack surface.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:ec2 | maven | < 1.48 | 1.48 |
Ongoing coverage of React2Shell