Path traversal in Blue Ocean - CVE-2020-2254
Published: September 16, 2020 / Updated: September 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the affected plugin provides an undocumented feature flag, "blueocean.features.GIT_READ_SAVE_TYPE", that when set to the value "clone". A remote authenticated attacker with Item/Configure or Item/Create permission can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
Red Hat OpenShift Container Platform
jenkins-2-plugins (Red Hat package)
How to mitigate CVE-2020-2254
jenkins-2-plugins (Red Hat package) - update to 3.11.1603460090-1.el7