Impact
The Jenkins File Parameter Plugin versions up to 425.v3fa_801681b_5e allow an attacker to write files to any location on the Jenkins controller by exploiting Stapler data binding. This flaw can be used to place malicious executables, modify configuration files, or otherwise compromise the controller platform, giving an attacker full remote code execution. The weakness is a file‑system path traversal issue identified as CWE‑22.
Affected Systems
All Jenkins deployments that use the File Parameter Plugin before 425.v3fa_801681b_5e are affected. Systems running any earlier release of the plugin are at risk of arbitrary file write operations on the controller’s file system.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. Although EPSS data is not available, the capability to write arbitrary files constitutes a direct attack vector that can be exploited through normal plugin operations, implying potential remote exploitation by users who can trigger the plugin. The flaw is not yet listed in the CISA KEV catalog, but its high impact warrants immediate attention.
OpenCVE Enrichment