Review reviewHigh

CVE-2026-33001

Jenkins Project Jenkins, OpenShift Developer Tools and Services 4.12, OpenShift Developer Tools and Services 4.13

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.

CVSS
8.8
EPSS
1.16%
64.0% percentile
CISA KEV
Not listed
Published
2026.03.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.16%
Technical severityCVSS 8.8

Vulnerability overview

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.

Affected product and versions

Product
Jenkins Project Jenkins, OpenShift Developer Tools and Services 4.12, OpenShift Developer Tools and Services 4.13
Affected versions
< 2.541.3, < 2.555
Fixed versions
2.541.3, 2.555

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Jenkins Project Jenkins, OpenShift Developer Tools and Services 4.12, OpenShift Developer Tools and Services 4.13 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-22, CWE-59
CVE-2026-33001 — Jenkins Project Jenkins, OpenShift Developer Tools and Services 4.12, OpenShift Developer Tools and Services 4.13 | SECUFOCUS NOW