Arbitrary File Write Vulnerability in Jenkins Cobertura Plugin by Jenkins
CVE-2020-2139

6.5MEDIUM

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
9 March 2020

What is CVE-2020-2139?

An arbitrary file write vulnerability exists in Jenkins Cobertura Plugin versions 1.15 and earlier. This flaw allows malicious actors who can manipulate the contents of coverage report files to overwrite any file on the Jenkins master file system. This capability poses a significant risk to the integrity of the Jenkins environment, facilitating unauthorized access to sensitive information or system configurations.

Affected Version(s)

Jenkins Cobertura Plugin <= 1.15

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.