Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70427

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

A flaw was found in Jenkins. Attackers who can control agent processes can exploit this vulnerability by providing specially crafted .tar or .tar.gz archives to the Jenkins controller. This is due to unsafe handling of symbolic links with effectively empty names during archive extraction. Successful exploitation allows an attacker to write files to arbitrary locations on the file system, potentially leading to unauthorized data modification or system compromise.

Отчет

Important: This flaw in Jenkins allows attackers who can control a Jenkins agent process to exploit unsafe handling of symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, writing files to arbitrary locations on the Jenkins controller's file system. This could result in arbitrary code execution and compromise of the Jenkins instance, for example by writing malicious scripts or plugins into the Jenkins home directory, but requires the attacker to already be able to run an agent process against the controller, limiting the attack surface to build infrastructure that is already at least partially trusted. This is an incomplete fix of a previously disclosed issue (CVE-2026-33001).

Меры по смягчению последствий

Until Jenkins is updated to a fixed version, restrict which users and systems are permitted to connect build agents to the Jenkins controller, and avoid running untrusted or externally triggered build jobs on agents that can return archives to the controller. Monitor the Jenkins controller's file system, in particular the init.groovy.d and plugins directories under the Jenkins home directory, for unauthorized changes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2511678jenkins: Jenkins: Arbitrary file write via crafted archives and symbolic links

EPSS

Процентиль: 16%
0.00248
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
14 дней назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

CVSS3: 4.3
github
14 дней назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.

EPSS

Процентиль: 16%
0.00248
Низкий

8.8 High

CVSS3