VULNERABILITY INTELLIGENCE
CVE-2020-2139
CVSS score6.5 MEDIUM
EPSS probability1.59%
CISA KEVNot currently listed
Published2020-03-09
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Description
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.
Weakness classification
- nvd@nist.gov: CWE-22
Primary references
- jenkinsci-cert@googlegroups.com — Third Party Advisory
- jenkinsci-cert@googlegroups.com — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory