Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2020-12-03/#SECURITY-2109%20(1) | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2020/12/03/2 | Mailing List Third Party Advisory |
Configurations
Information
Published : 2020-12-03 16:15
Updated : 2021-10-19 12:12
NVD link : CVE-2020-2322
Mitre link : CVE-2020-2322
JSON object : View
Products Affected
netflix
- chaos_monkey
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
