AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-2278

MEDIUM · CVSS 6.5 EPSS 1.41%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-09-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-2278
Severity
MEDIUM
CVSS
6.5
EPSS
1.41%
Jenkins

Original NVD Description

Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to replace any other '.xml' file on the Jenkins controller with a job config.xml file's content.