PT-2020-15350 · Jenkins · Jenkins Cobertura Plugin+1
Federico Pellegrin
·
Published
2020-03-09
·
Updated
2023-10-25
·
CVE-2020-2139
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Jenkins Cobertura Plugin versions 1.15 and earlier
Description
The issue allows attackers who can control the coverage report file contents to overwrite any file on the Jenkins master file system. This is due to an arbitrary file write vulnerability. The Cobertura Plugin 1.16 sanitizes the file paths to prevent escape from the base directory, indicating that versions prior to 1.16 are affected.
Recommendations
For Jenkins Cobertura Plugin versions 1.15 and earlier, update to version 1.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the coverage report file contents to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Cobertura Plugin