Impact
The Groovy Libraries Plugin in Jenkins Pipeline allows a library step to specify any file path. In versions up to 805.va_fc79344957d the plugin does not enforce that the path is within the SCM checkout; it follows symbolic links that can point outside the workspace. This pathname traversal flaw enables a user who can configure pipeline scripts to read arbitrary files from the Jenkins controller’s file system and delete files in non‑workspace directories, compromising confidentiality and integrity.
Affected Systems
Jenkins Pipeline Groovy Libraries Plugin 805.va_fc79344957d and earlier. These versions are part of the Jenkins Project (Jenkins Pipeline) plugin set used for building continuous‑integration pipelines. Any Jenkins installation that has these plugin versions installed is vulnerable. The vulnerability does not, however, affect newer releases past 805.va_fc79344957d.
Risk and Exploitability
The CVSS base score of 4.2 indicates moderate severity. The EPSS score of less than 1% reflects a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The attack can be carried out only by users who have the authority to author or modify pipeline code, so it is inferred that the attacker must have at least pipeline configuration privileges on the Jenkins controller. Once privileged, the attacker can supply a library path that resolves outside the SCM checkout, read sensitive files, or delete files in arbitrary directories.
OpenCVE Enrichment