Описание
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
A flaw was found in Jenkins. Attackers who can control agent processes can exploit this vulnerability by providing specially crafted .tar or .tar.gz archives to the Jenkins controller. This is due to unsafe handling of symbolic links with effectively empty names during archive extraction. Successful exploitation allows an attacker to write files to arbitrary locations on the file system, potentially leading to unauthorized data modification or system compromise.
Отчет
Important: This flaw in Jenkins allows attackers who can control a Jenkins agent process to exploit unsafe handling of symbolic links with effectively empty names during the extraction of .tar and .tar.gz archives, writing files to arbitrary locations on the Jenkins controller's file system. This could result in arbitrary code execution and compromise of the Jenkins instance, for example by writing malicious scripts or plugins into the Jenkins home directory, but requires the attacker to already be able to run an agent process against the controller, limiting the attack surface to build infrastructure that is already at least partially trusted. This is an incomplete fix of a previously disclosed issue (CVE-2026-33001).
Меры по смягчению последствий
Until Jenkins is updated to a fixed version, restrict which users and systems are permitted to connect build agents to the Jenkins controller, and avoid running untrusted or externally triggered build jobs on agents that can return archives to the controller. Monitor the Jenkins controller's file system, in particular the init.groovy.d and plugins directories under the Jenkins home directory, for unauthorized changes.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
EPSS
8.8 High
CVSS3