Database/Control plane, storage & DevOps
Jenkins ThinBackup plugin: attacker redirects backups and pulls arbitrary controller files into them
Impact
A low-privileged user can overwrite the plugin's backup configuration through Stapler data binding, choosing both the destination directory the backup is written to and which controller files are included in it. That converts the backup job into an arbitrary read of the Jenkins controller filesystem, delivered somewhere the attacker chooses - and the controller filesystem is where credentials.xml, the master key, kubeconfigs for the training clusters and registry tokens live. Jenkins scores it 7.1, high confidentiality with low integrity impact, and claims no code execution; for a controller that provisions GPU cluster jobs, disclosure of its credential store gets to the same place one step later. Only controllers with ThinBackup installed are affected.
Who can reach it
Remote authenticated Jenkins user with low privileges (PR:L). No administrator rights, no user interaction, no access to the backup destination beforehand.
What to do
Upgrade ThinBackup past 2.1.4 per SECURITY-4099 in the 2026-09-02 Jenkins advisory; the advisory names 2.1.4 and earlier as affected and does not state a fixed version, so take the current plugin release. Cost is a controller restart to load the plugin - queued builds pause and agents reconnect. Check existing backup destinations and the plugin's configured include paths for unexpected values, and if either looks tampered with, rotate every credential held on the controller.
References
Related entries
- Flux CD (allow-webhooks NetworkPolicy, notification-controller event server): CROSS-TENANT EVENT FORGERY: theNCVD-2026-057-flux-cd-allow-webhooks-networkpo · Flux CD (allow-webhooks NetworkPolicy, notification-controller event server)High
- OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bitCVE-2023-51767 · OpenSSH through 10.0 - mm_answer_authpassword uses an integer 'authenticated' flag that does not resist a single bit…High
- AMD Radeon RGB tool - signature verification on files in the installation directory: The Radeon RGB tool doesCVE-2024-36334 · AMD Radeon RGB tool - signature verification on files in the installation directoryHigh
- Intel Neural Compressor (SQL injection, second instance): A second SQL-injection path in Neural Compressor reachableCVE-2024-39766 · Intel Neural Compressor (SQL injection, second instance)High
- Redis: Authenticated user triggers a stack/heap out-of-bounds write in hyperloglog opsCVE-2025-32023 · RedisHigh
- Redis (multi-bulk command protocol handling): PERMANENT, VENDOR-ACKNOWLEDGED DENIAL OF SERVICE WITH NO FIX PLANNED. AnNCVD-2025-021-redis-multi-bulk-command-protoco · Redis (multi-bulk command protocol handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.