Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Elie Metahri

Pesquisador deAirbus Protect Offensive Security Team
#19587de 53,635
13.3CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2026-26073
9.0
2026-03-18
Jenkins · Jenkins · CVE-2026-33001
**Name of the Vulnerable Software and Affected Versions** Jenkins versions 2.554 and earlier Jenkins LTS versions 2.541.2 and earlier **Description** The software does not safely handle symbolic links when extracting .tar and .tar.gz archives. This allows crafted archives to write files to arbitrary locations on the filesystem, limited by the file system access permissions of the user running Jenkins. An attacker with Item/Configure permission, or control over agent processes, can exploit this to deploy malicious scripts or plugins on the controller. **Recommendations** Update Jenkins to a version later than 2.554. Update Jenkins LTS to a version later than 2.541.2.
PT-2026-26076
4.3
2026-03-18
Jenkins · Jenkins Loadninja Plugin · CVE-2026-33004
**Name of the Vulnerable Software and Affected Versions** Jenkins LoadNinja Plugin versions 2.1 and earlier **Description** The Jenkins LoadNinja Plugin does not properly mask LoadNinja API keys as they are displayed on the job configuration form. This could allow attackers to observe and capture these keys. **Recommendations** Update to a newer version of the Jenkins LoadNinja Plugin that addresses this issue.