Impact
Jenkins versions 2.575 and earlier, including LTS 2.568.1 and earlier, contain a flaw in the handling of file parameter names. The flaw allows an authenticated user who has Item/Configure and Item/Build permissions to craft a path that traverses outside the intended destination and write files anywhere on the controller’s file system. This can compromise critical files, overwrite executables, or place malicious payloads that may later be executed, representing a significant loss of confidentiality, integrity, and availability.
Affected Systems
The affected product is Jenkins from the Jenkins Project. Vulnerable releases include all versions up to and including 2.575 for the mainline and 2.568.1 for the long‑term support branch.
Risk and Exploitability
The CVSS score is not disclosed, but the capability to write to arbitrary locations gives the attacker control over system files. Exploitation requires legitimate Jenkins credentials with Item/Configure and Item/Build privileges, which can be obtained by an attacker who gains access to a user account or through social engineering. Because the flaw is triggered by normal API or web form input, the attack vector is inferred to be remote via Jenkins’ web interface or API. The lack of an EPSS score or KEV listing does not diminish the potential impact; the attack remains valuable to adversaries such as credential‑stealers or script‑based intruders.
OpenCVE Enrichment