Arbitrary File Write Vulnerability in Jenkins Cobertura Plugin by Jenkins
CVE-2020-2139

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
9 March 2020

Summary

An arbitrary file write vulnerability exists in Jenkins Cobertura Plugin versions 1.15 and earlier. This flaw allows malicious actors who can manipulate the contents of coverage report files to overwrite any file on the Jenkins master file system. This capability poses a significant risk to the integrity of the Jenkins environment, facilitating unauthorized access to sensitive information or system configurations.

Affected Version(s)

Jenkins Cobertura Plugin <= 1.15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.