CVE-2020-2286: Jenkins Role-Based Authorization Strategy

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration.

Affected products

  • Jenkins Role-Based Authorization Strategy: up to and including 3.0

Published 2020-10-08. Last modified 2026-06-17.