Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not …
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
References
- Jenkins Security Advisory 2026-03-18 vendor-advisory
Affected products
- <2.541.*
- *
Matching in nixpkgs
pkgs.jenkins
Extendable open source continuous integration server
pkgs.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
pkgs.python312Packages.jenkinsapi
Python API for accessing resources on a Jenkins continuous-integration server
pkgs.python313Packages.jenkinsapi
Python API for accessing resources on a Jenkins continuous-integration server
pkgs.python314Packages.jenkinsapi
Python API for accessing resources on a Jenkins continuous-integration server
pkgs.python312Packages.python-jenkins
Python bindings for the remote Jenkins API
pkgs.python313Packages.python-jenkins
Python bindings for the remote Jenkins API
pkgs.python314Packages.python-jenkins
Python bindings for the remote Jenkins API
pkgs.python312Packages.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
pkgs.python313Packages.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
pkgs.python314Packages.jenkins-job-builder
Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git
Package maintainers
-
@NeQuissimus Tim Steinbach <tim@nequissimus.com>
-
@coreyoconnor Corey O'Connor <coreyoconnor@gmail.com>
-
@earldouglas James Earl Douglas <james@earldouglas.com>
-
@Bot-wxt1221 Bot-wxt1221 <3264117476@qq.com>
-
@invokes-su Souvik Sen <nixpkgs-commits@deshaw.com>
-
@drets Dmytro Rets <dmitryrets@gmail.com>
-
@de11n Elliot Cameron <nixpkgs-commits@deshaw.com>
-
@gador Florian Brandes <florian.brandes@posteo.de>
-
@despsyched Priyanshu Tripathi <priyanshu.tripathi@deshaw.com>