Arbitrary File Write Vulnerability in Jenkins Cobertura Plugin by Jenkins
CVE-2020-2139
6.5MEDIUM
Summary
An arbitrary file write vulnerability exists in Jenkins Cobertura Plugin versions 1.15 and earlier. This flaw allows malicious actors who can manipulate the contents of coverage report files to overwrite any file on the Jenkins master file system. This capability poses a significant risk to the integrity of the Jenkins environment, facilitating unauthorized access to sensitive information or system configurations.
Affected Version(s)
Jenkins Cobertura Plugin <= 1.15
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved