GHSA-m935-chfp-9f63
GitHub Security Advisory
Arbitrary file write vulnerability in Jenkins Cobertura Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system. Cobertura Plugin 1.16 sanitizes the file paths to prevent escape from the base directory.
Affected Packages
Maven
org.jenkins-ci.plugins:cobertura
Affected versions:
0
(fixed in 1.16)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.