SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-2275

Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

MEDIUM 6.5EPSS 1.70%

Does this matter?

Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.

Description

Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.70% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
jenkins/copy data to workspace
Source
jenkinsci-cert@googlegroups.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.