CVE-2020-2275
Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.
Date published : 2020-09-16
https://www.jenkins.io/security/advisory/2020-09-16/#SECURITY-1966