CVE-2020-2296: Jenkins Shared Objects

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.

Affected products

  • Jenkins Shared Objects: up to and including 0.44

Published 2020-10-08. Last modified 2026-06-17.