Impact
The Jenkins TICS Plugin contains an OS command injection flaw in versions 2025.1.1 and earlier. The flaw lets an attacker influence the values of build environment variables, which the plugin blindly passes to the underlying operating system. Through this, an attacker can execute arbitrary shell commands on the agent that runs the build, compromising the entire build environment.
Affected Systems
The vulnerability affects the Jenkins Project Jenkins TICS Plugin, specifically all releases up to and including 2025.1.1. Instances that run a Jenkins master with an affected plugin version and allow users to set environment variables in build jobs are susceptible. This includes on‑premise Jenkins installations and any self‑hosted Jenkins instance that has not upgraded past 2025.1.1.
Risk and Exploitability
It has a CVSS score of 7.4, indicating a high severity. The EPSS score is not provided, and the issue is not currently listed in CISA's KEV catalog. Attackers can exploit the flaw if they can create or modify jobs to inject malicious environment variables, a privilege that typically requires at least job‑configuration rights. An unauthenticated attacker cannot trigger the flaw unless additional weaknesses allow arbitrary job manipulation. Since the plugin does not perform input validation, the exploitation path is straightforward once the necessary permissions are obtained.
OpenCVE Enrichment