jenkins-core is vulnerable to Path Traversal
80
High Risk
File parameter name checks fail to catch some path traversal patterns. An attacker with Item/Configure and Item/Build permission can write files to arbitrary locations on the controller filesystem, including paths that lead to code execution such as JENKINS_HOME/init.groovy.d/ or JENKINS_HOME/plugins/. The fix improves detection of traversal in file parameter names so those writes are blocked.
You are affected if you are using a version that falls within the vulnerable range and users with Item/Configure and Item/Build permission can submit file parameters.
jenkins-core is vulnerable to Path Traversal in versions 0.0.1 - 2.568.1 and 2.569 - 2.575.
Upgrade the org.jenkins-ci.main:jenkins-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant