CVE-2020-2293: Jenkins Persona

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller.

Affected products

  • Jenkins Persona: up to and including 2.4

Published 2020-10-08. Last modified 2026-06-17.