Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-70427

Опубликовано: 05 авг. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
redhat
14 дней назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

CVSS3: 4.3
github
14 дней назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

EPSS

Процентиль: 16%
0.00248
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-59