Impact
The Jenkins Robot Framework Plugin versions 6.2.2 and earlier fails to verify that the directory used to store Robot Framework report archives is within the Jenkins workspace. This omission allows a user with Item/Configure permission to write arbitrary files with chosen content to the Jenkins controller filesystem. An attacker could place malicious executables or scripts in privileged locations, resulting in the ability to execute code remotely and compromise the entire Jenkins environment.
Affected Systems
Jenkins Project users running Jenkins Robot Framework Plugin 6.2.2 or earlier are affected. The vulnerability is present in the Robot Framework Plugin distributed by the Jenkins Project and targets any system where the plugin is installed without a newer, patched version.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and despite an EPSS score of less than 1 %, the bug can be exploited remotely by any authorized user with Item/Configure rights. Because the attacker can create or replace files on the controller, exploitation bypasses authentication but requires legitimate workspace permissions. The vulnerability is not listed in CISA KEV, but organizations already prioritizing secure Jenkins configurations should consider it priority because of the potential for remote code execution.
OpenCVE Enrichment