CyberRota Analysis
AI-GeneratedJenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable due to improper handling of symbolic links with empty names during the extraction of `.tar` and `.tar.gz` archives. This flaw allows attackers with control over agent processes to craft malicious archives, potentially writing files to arbitrary locations on the file system based on the permissions of the Jenkins user. Organizations utilizing affected Jenkins versions should prioritize patching to mitigate the risk of unauthorized file system access.
Original NVD Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.