CVEs Blog | G5 Cyber Security

CVE-2020-2254 – Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented fea

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2254

Reference (s):

Exit mobile version