jenkins-core is vulnerable to Improper Link Resolution Before File Access
82
High Risk
Archive extraction for .tar and .tar.gz files does not safely handle symbolic links whose names are effectively empty. An attacker who controls an agent process can send a crafted archive so the controller writes files outside the intended extract location, including under JENKINS_HOME/init.groovy.d/ or JENKINS_HOME/plugins/, which can lead to code execution. The fix refuses to extract archives that contain those symbolic links.
You are affected if you are using a version that falls within the vulnerable range and attackers can control agent processes that send archives to the controller.
jenkins-core is vulnerable to Improper Link Resolution Before File Access in versions 0.0.1 - 2.568.1 and 2.569 - 2.575.
Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant