Jenkins Security Advisory 2020-10-08
Affects plugin: Active Choices Affects plugin: Audit Trail Affects plugin: couchdb-statistics Affects plugin: Maven Cascade Release Affects plugin: Nerrvana Affects plugin: Persona Affects plugin: Release Affects plugin: Role-based Authorization Strategy Affects plugin: Shared Objects Affects plugin: SMS Notification
CSIRTS triage
- What
- Multiple security vulnerabilities have been identified affecting various Jenkins plugins.
- Who is affected
- All deployments using the affected plugins are at risk.
- Urgency
- Remediation is necessary as vulnerabilities can lead to potential exploitation.
- Action
- Update to the latest versions of the affected Jenkins plugins.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins Plugins
Get an email when a new Jenkins Plugins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.jenkins.io/security/advisory/2020-10-08/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2020-22861.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-22871.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 65% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22880.95% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22890.91% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22900.90% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22910.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22920.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-22931.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22940.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-22950.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2020-2286 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2287 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2288 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2289 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2290 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2291 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2292 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2293 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2294 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2295 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2296 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2297 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-2298 | coverage & exploitation status | NVD · CVE.org |
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-08-052026-08-05
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-06-102026-06-10
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29