CVE-2020-2323: Netflix Chaos Monkey

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.

Affected products

  • Netflix Chaos Monkey: up to and including 0.4

Published 2020-12-03. Last modified 2026-06-17.