PT-2020-15350 · Jenkins · Jenkins Cobertura Plugin+1

Federico Pellegrin

·

Published

2020-03-09

·

Updated

2023-10-25

·

CVE-2020-2139

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins Cobertura Plugin versions 1.15 and earlier
Description The issue allows attackers who can control the coverage report file contents to overwrite any file on the Jenkins master file system. This is due to an arbitrary file write vulnerability. The Cobertura Plugin 1.16 sanitizes the file paths to prevent escape from the base directory, indicating that versions prior to 1.16 are affected.
Recommendations For Jenkins Cobertura Plugin versions 1.15 and earlier, update to version 1.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the coverage report file contents to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-2139
GHSA-M935-CHFP-9F63

Affected Products

Jenkins
Jenkins Cobertura Plugin