First published: Mon Mar 09 2020(Updated: )
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Cobertura | <=1.15 | |
maven/org.jenkins-ci.plugins:cobertura | <=1.15 | 1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2139 is rated as high severity due to its potential for arbitrary file writes on the Jenkins master file system.
To fix CVE-2020-2139, upgrade the Jenkins Cobertura Plugin to version 1.16 or later.
CVE-2020-2139 affects users of Jenkins Cobertura Plugin versions 1.15 and earlier.
Attackers can exploit CVE-2020-2139 to overwrite any file on the Jenkins master file system if they control the coverage report file contents.
CVE-2020-2139 is not a remote code execution vulnerability, but it allows unauthorized file overwriting which could lead to further exploitation.