CVE-2020-2139
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
09/03/2020
Last modified:
25/10/2023
Description
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:cobertura:*:*:*:*:*:jenkins:*:* | 1.15 (including) |
To consult the complete list of CPE names with products and versions, see this page



