CVE-2020-2139: Jenkins Cobertura
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.
Affected products
- Jenkins Cobertura: up to and including 1.15
Published 2020-03-09. Last modified 2026-06-17.