Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48921

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

A flaw was found in the Jenkins Pipeline: Groovy Libraries Plugin. This vulnerability allows an attacker, who can control the content of a library used by a Pipeline job, to read arbitrary files from the Jenkins controller filesystem. This could lead to the disclosure of sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-2-pluginsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-agent-base-rhel9Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2482211pipeline-groovy-lib: Jenkins Pipeline Groovy Libraries Plugin: Information disclosure via symbolic links in shared libraries

EPSS

Процентиль: 22%
0.00301
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

CVSS3: 7.5
github
2 месяца назад

Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries

EPSS

Процентиль: 22%
0.00301
Низкий

5.5 Medium

CVSS3