Vulnerability record · CVE-2023-32986 · published 16 May 2023
CVE-2023-32986: Jenkins File Parameter Plugin arbitrary file write via unrestricted parameter name
Jenkins · File Parameters
The Jenkins File Parameter Plugin (285.v757c5b_67a_c25 and earlier) does not restrict the name of Stashed File Parameters, so the resulting uploaded file name can be attacker-controlled. An attacker with Item/Configure permission can therefore create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
Description
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact and a very high EPSS percentile, though it requires authenticated Item/Configure permission and is not in KEV.
What it is
The Jenkins File Parameter Plugin (285.v757c5b_67a_c25 and earlier) does not restrict the name of Stashed File Parameters, so the resulting uploaded file name can be attacker-controlled. An attacker with Item/Configure permission can therefore create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
Impact
An attacker gains the ability to write files anywhere the Jenkins controller process can write, which can overwrite configuration, scripts or plugin files and lead to code execution or full controller compromise.
Attack surface
Reached over the network through the Jenkins web interface by an authenticated user holding Item/Configure permission; no user interaction is required. The CVSS vector (AV:N/AC:L/PR:L/UI:N) confirms network reachability with low privileges and no UI.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at 0.60683 (99.1st percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade the Jenkins File Parameter Plugin to a version newer than 285.v757c5b_67a_c25 that fixes SECURITY-3123.
- Restrict Item/Configure permission to trusted users only, since the flaw requires that permission.
- Audit and remove unnecessary Item/Configure grants across jobs and folders.
- Monitor the Jenkins controller file system for unexpected file creation or modification in plugin, config and script directories.
Detection
- Review Jenkins audit logs for Item/Configure permission use and configuration changes by unexpected accounts.
- Monitor controller file system for new or modified files outside normal build and job directories.
- Alert on Stashed File Parameter names containing path separators or traversal sequences.
- Correlate Jenkins controller file writes with subsequent process execution or plugin reload events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3123 | Vendor Advisory |
| https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3123 | Vendor Advisory |
Track CVE-2023-32986 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32986), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.