CVE-2020-2139

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
09/03/2020
Last modified:
25/10/2023

Description

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:cobertura:*:*:*:*:*:jenkins:*:* 1.15 (including)