CVE-2020-2275: Jenkins Copy Data To Workspace

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

Affected products

  • Jenkins Copy Data To Workspace: up to and including 1.0

Published 2020-09-16. Last modified 2026-06-17.