File Reading Vulnerability in Jenkins Blue Ocean Plugin by CloudBees
CVE-2020-2254
6.5MEDIUM
What is CVE-2020-2254?
The Jenkins Blue Ocean Plugin, up to version 1.23.2, introduces a significant risk through an undocumented feature flag. When this flag is enabled, it grants users with Job/Configure or Job/Create permissions the ability to access and read arbitrary files stored on the Jenkins controller's file system. This vulnerability exposes sensitive information and could be exploited if not properly mitigated. Users are advised to review their plugin configurations and apply necessary updates.
Affected Version(s)
Jenkins Blue Ocean Plugin <= 1.23.2
Jenkins Blue Ocean Plugin 1.19.2