Impact
The Jenkins ThinBackup Plugin allows an attacker to overwrite the backup configuration through Stapler data binding. By doing so, the attacker can redirect backup writes to a directory of their choice and include arbitrary files from the Jenkins controller file system in the backup. This vulnerability exposes sensitive files that may be unintentionally captured and stored in backups, potentially leading to confidentiality breaches.
Affected Systems
Jenkins Project's ThinBackup Plugin versions 2.1.4 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS is not available and the issue is not listed in KEV, suggesting it may not yet have seen widespread exploitation. The attack vector is likely a web application-based data binding flaw, requiring authenticated access to the Jenkins instance. If an attacker can authenticate or manipulate the API, they can change backup destinations to arbitrary paths, causing sensitive files to be included in subsequent backups.
OpenCVE Enrichment