File Reading Vulnerability in Jenkins Blue Ocean Plugin by CloudBees
CVE-2020-2254

6.5MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
16 September 2020

Summary

The Jenkins Blue Ocean Plugin, up to version 1.23.2, introduces a significant risk through an undocumented feature flag. When this flag is enabled, it grants users with Job/Configure or Job/Create permissions the ability to access and read arbitrary files stored on the Jenkins controller's file system. This vulnerability exposes sensitive information and could be exploited if not properly mitigated. Users are advised to review their plugin configurations and apply necessary updates.

Affected Version(s)

Jenkins Blue Ocean Plugin <= 1.23.2

Jenkins Blue Ocean Plugin 1.19.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.