vulnerability

Red Hat OpenShift: CVE-2020-2254: jenkins-2-plugins/blueocean: Path traversal vulnerability in Blue Ocean Plugin could allow to read arbitrary files

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:P/I:N/A:N)
Published
Sep 16, 2020
Added
Dec 29, 2020
Modified
Aug 11, 2025

Description

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

Solution

linuxrpm-upgrade-jenkins-2-plugins
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.