← Back to CVE List

CVE-2020-2254

Published: 2020-09-16T14:15Z
Last Modified: 2024-11-21T05:25Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt