CyberRota Analysis
AI-GeneratedJenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable to improper path traversal in file parameter names, enabling users with Item/Configure and Item/Build permissions to write files to arbitrary locations on the controller's file system. This flaw could lead to unauthorized file manipulation, potentially compromising the integrity of the Jenkins environment. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.