CVE-2020-2286: Jenkins Role-Based Authorization Strategy
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration.
Affected products
- Jenkins Role-Based Authorization Strategy: up to and including 3.0
Published 2020-10-08. Last modified 2026-06-17.