Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jvnet.hudson.plugins:copy-data-to-workspace-plugin(Maven) | 0 | N/A | N/A |
CVSS Metrics