GHSA-p2rf-wpxj-mx2g

Suggest an improvement
Source
https://github.com/advisories/GHSA-p2rf-wpxj-mx2g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-p2rf-wpxj-mx2g/GHSA-p2rf-wpxj-mx2g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p2rf-wpxj-mx2g
Aliases
Published
2026-04-29T15:30:38Z
Modified
2026-05-06T23:11:23Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins Credentials Binding Plugin has a path traversal vulnerability
Details

Jenkins Credentials Binding Plugin versions 719.v80e905ef14eb_ and earlier do not sanitize file names for file and zip file credentials.

This allows attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem. If Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node, this can lead to remote code execution.

Credentials Binding Plugin 720.v3f6decef43ea_ sanitizes the file name provided for file and zip file credentials, preventing path traversal.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-06T22:45:55Z",
    "nvd_published_at": "2026-04-29T14:16:19Z",
    "severity": "HIGH"
}
References

Affected packages

Maven / org.jenkins-ci.plugins:credentials-binding

Package

Name
org.jenkins-ci.plugins:credentials-binding
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/credentials-binding

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
720.v3f6decef43ea

Affected versions

1.*
1.0-beta-1
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.17
1.18
1.19
1.20
1.20.1
1.21
1.22
1.23
1.24
1.24.1
1.25
1.26
1.27
1.27.1
523.*
523.vd859a_4b_122e6
523.525.vb_72269281873
604.*
604.vb_64480b_c56ca_
621.*
621.v58c0fb_d285a_c
626.*
626.v8d9034b_8ea_cc
631.*
631.v861c06d062b_4
636.*
636.v55f1275c7b_27
642.*
642.v737c34dea_6c2
657.*
657.v2b_19db_7d6e6d
677.*
677.vdc9d38cb_254d
679.*
679.v6288482e873c
681.*
681.vf91669a_32e45
687.*
687.v619cb_15e923f
687.689.v1a_f775332fc9
696.*
696.v256688029804
702.*
702.vfe613e537e88
717.*
717.v951d49b_5f3a_a_
719.*
719.v80e905ef14eb_

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-p2rf-wpxj-mx2g/GHSA-p2rf-wpxj-mx2g.json"