← Vulnerability feed

Vulnerability record · CVE-2023-32986 · published 16 May 2023

CVE-2023-32986: Jenkins File Parameter Plugin arbitrary file write via unrestricted parameter name

Jenkins · File Parameters

The Jenkins File Parameter Plugin (285.v757c5b_67a_c25 and earlier) does not restrict the name of Stashed File Parameters, so the resulting uploaded file name can be attacker-controlled. An attacker with Item/Configure permission can therefore create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

8.8 CVSS 3.1 High EPSS 61% · top 0.9% CWE-732 · Incorrect permission assignment
8.8CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with high confidentiality, integrity and availability impact and a very high EPSS percentile, though it requires authenticated Item/Configure permission and is not in KEV.

What it is

The Jenkins File Parameter Plugin (285.v757c5b_67a_c25 and earlier) does not restrict the name of Stashed File Parameters, so the resulting uploaded file name can be attacker-controlled. An attacker with Item/Configure permission can therefore create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

Impact

An attacker gains the ability to write files anywhere the Jenkins controller process can write, which can overwrite configuration, scripts or plugin files and lead to code execution or full controller compromise.

Attack surface

Reached over the network through the Jenkins web interface by an authenticated user holding Item/Configure permission; no user interaction is required. The CVSS vector (AV:N/AC:L/PR:L/UI:N) confirms network reachability with low privileges and no UI.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at 0.60683 (99.1st percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade the Jenkins File Parameter Plugin to a version newer than 285.v757c5b_67a_c25 that fixes SECURITY-3123.
  • Restrict Item/Configure permission to trusted users only, since the flaw requires that permission.
  • Audit and remove unnecessary Item/Configure grants across jobs and folders.
  • Monitor the Jenkins controller file system for unexpected file creation or modification in plugin, config and script directories.

Detection

  • Review Jenkins audit logs for Item/Configure permission use and configuration changes by unexpected accounts.
  • Monitor controller file system for new or modified files outside normal build and job directories.
  • Alert on Stashed File Parameter names containing path separators or traversal sequences.
  • Correlate Jenkins controller file writes with subsequent process execution or plugin reload events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32986 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2023-32986), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.