CVE-2020-2254: Jenkins Blue Ocean

Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

Affected products

  • Jenkins Blue Ocean: up to and including 1.23.2

Published 2020-09-16. Last modified 2026-06-17.