Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvrr-fjq7-cfrw

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
redhat
14 дней назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

CVSS3: 4.3
nvd
14 дней назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-59