GHSA-jx7x-rf3f-j644
GitHub Security Advisory
Jenkins CloudBees CD Plugin vulnerable to arbitrary file deletion
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
In Jenkins CloudBees CD Plugin, artifacts that were previously copied from an agent to the controller are deleted after publishing by the 'CloudBees CD - Publish Artifact' post-build step.
CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during this cleanup process.
This allows attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system.
CloudBees CD Plugin 1.1.33 deletes symbolic links without following them.
Affected Packages
Maven
org.jenkins-ci.plugins:electricflow
Affected versions:
0
(fixed in 1.1.33)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.