ZeroHour

CVE-2020-2275

CVSS 3.1
6.5 medium
EPSS
2%p76
Published
()
Modified
Description

Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

Vendors
jenkins
Products
copy data to workspace
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.