GHSA-2f4c-8rp6-fh6q
Dashboard / Vulnerabilities / GHSA-2f4c-8rp6-fh6q
Summary: Arbitrary file read vulnerability in Copy data to workspace Jenkins Plugin
Details: Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2275, https://github.com/jenkinsci/copy-data-to-workspace-plugin, https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1966, http://www.openwall.com/lists/oss-security/2020/09/16/3
Affected packages
Package
Name: org.jvnet.hudson.plugins:copy-data-to-workspace-plugin
Purl: pkg:maven/org.jvnet.hudson.plugins/copy-data-to-workspace-plugin
Affected ranges
Type: ECOSYSTEM
Events:
