#VU46961 Path traversal in Storable Configs - CVE-2020-2278
Published: September 16, 2020 / Updated: September 22, 2020
Storable Configs
Jenkins
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the affected plugin does not restrict the user-specified file name. A remote authenticated attacker can replace any other ".xml" file on the Jenkins controller with the job’s "config.xml" file’s content.