CVE-2020-2278 affects Jenkins Storable Configs Plugin versions 1.0 and earlier. This vulnerability allows authenticated attackers with Job/Configure permissions to overwrite arbitrary .xml files on the Jenkins controller by manipulating the file name during job configuration. Rated as MEDIUM severity with a CVSS score of 6.5, the vulnerability has a low attack complexity and requires low privileges, but can lead to high integrity impact by allowing unauthorized file replacement. There is no confidentiality or availability impact. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:jenkins:storable_configs:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.