Database/Control plane, storage & DevOps
Jenkins File Parameter Plugin: arbitrary file write on the controller via data binding leads to RCE
Impact
The plugin allows writing files to arbitrary locations on the Jenkins controller filesystem through Stapler data binding, which the advisory states can lead to remote code execution. Arbitrary write on a controller is a short path to persistence - init scripts, plugin directories, cron - and from there to the credentials that let the controller deploy onto the GPU fleet. Anything the controller can push to, including container registries and cluster API endpoints, inherits the compromise. Affects File Parameter Plugin 425.v3fa_801681b_5e and earlier.
Who can reach it
An authenticated Jenkins user with low privileges reaching the data binding path. No user interaction required.
What to do
Update the File Parameter Plugin past 425.v3fa_801681b_5e and restart the controller; the record does not name the fixed release. If the plugin is not in use, remove it. After patching, check the controller filesystem and plugin directory for unexpected files, since an upgrade does not remove anything already written. Short CI outage.
References
Related entries
- Jenkins Entra ID plugin: a colliding Entra group display name inherits a privileged group's permissionsCVE-2026-84672 · Jenkins Microsoft Entra ID plugin (group authorization by display name)High
- KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes APINCVD-2026-051-kubeedge-configupdatejob-handler · KubeEdge (ConfigUpdateJob handler, updateFields)High
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheNCVD-2026-052-kubeedge-nodeupgradejob-handler · KubeEdge (NodeUpgradeJob handler, v1alpha2 API)High
- APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webCVE-2024-58310 · APC Network Management Card 4 (NMC4)High
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysCVE-2025-20163 · Cisco Nexus Dashboard Fabric Controller (SSH host key validation)High
- MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowingCVE-2025-31489 · MinIO (S3 API, unsigned-trailer uploads)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.