Количество 5
Количество 5
CVE-2026-33001
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
CVE-2026-33001
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
GHSA-r6qv-frpc-q66c
Jenkins has a link following vulnerability allows arbitrary file creation
BDU:2026-04250
Уязвимость сервера автоматизации Jenkins, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю записывать произвольные файлы
ROS-20260524-73-0044
Уязвимость jenkins
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33001 Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-33001 Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
GHSA-r6qv-frpc-q66c Jenkins has a link following vulnerability allows arbitrary file creation | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
BDU:2026-04250 Уязвимость сервера автоматизации Jenkins, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю записывать произвольные файлы | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
ROS-20260524-73-0044 Уязвимость jenkins | CVSS3: 8.8 | 1% Низкий | 2 месяца назад |
Уязвимостей на страницу