PT-2020-15504 · Jenkins · Jenkins Copy Data To Workspace Plugin+1

Daniel Beck

·

Published

2020-09-16

·

Updated

2023-10-25

·

CVE-2020-2275

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Copy data to workspace Plugin versions 1.0 and earlier
Description The issue allows attackers with Job/Configure permission to read arbitrary files on the Jenkins controller due to a lack of limitation on which directories can be copied from the controller to job workspaces.
Recommendations For Jenkins Copy data to workspace Plugin versions 1.0 and earlier, update to a version that limits directory copying to prevent arbitrary file reading.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-2275
GHSA-2F4C-8RP6-FH6Q

Affected Products

Jenkins
Jenkins Copy Data To Workspace Plugin