Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://jenkins.io/security/advisory/2020-05-06/#SECURITY-988 | vendor advisory |
http://www.openwall.com/lists/oss-security/2020/05/06/3 | third party advisory mailing list |