PT-2025-50361 · WordPress+1 · Jenkins Redpen - Pipeline Reporter For Jira Plugin+1

Yaroslav Afenkin

·

Published

2025-12-10

·

Updated

2025-12-14

·

CVE-2025-67643

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Redpen - Pipeline Reporter for Jira Plugin versions 1.054.v7b 9517b 6b 202 and earlier
Description The Jenkins Redpen - Pipeline Reporter for Jira Plugin does not properly validate file paths within the workspace directory during artifact uploads to Jira. This allows individuals with Item/Configure permissions to access files located on the Jenkins controller's workspace directory. The issue arises from insufficient path validation, potentially enabling unauthorized file retrieval.
Recommendations Update Jenkins Redpen - Pipeline Reporter for Jira Plugin to a version later than 1.054.v7b 9517b 6b 202.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-15979
CVE-2025-67643
GHSA-QXH4-J39M-QFX4

Affected Products

Jenkins
Jenkins Redpen - Pipeline Reporter For Jira Plugin