Back

MEDIUM

jenkins-2-plugins/blueocean: Path traversal vulnerability in Blue Ocean Plugin could allow to read arbitrary files

Published Sep 16, 2020

Description

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner jenkins
Published Sep 16, 2020
Updated Aug 4, 2024
Reserved Dec 5, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Sep 16, 2020
Bugzilla 1880456

ENISA EUVD

Assigner jenkins
Published Sep 16, 2020
Updated Aug 4, 2024