
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67643 is a path traversal vulnerability in the Jenkins Redpen - Pipeline Reporter for Jira Plugin (SECURITY-3290) that allows authenticated attackers with Item/Configure permission to read arbitrary files from the Jenkins controller's workspace directory. It affects plugin versions up to and including 1.054.v7b_9517b_6b_202. The vulnerability was disclosed on December 10, 2025, as part of a Jenkins security advisory. It carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, GitHub Advisory).
The root cause is improper path validation (CWE-22 — Path Traversal) when the plugin uploads artifacts to Jira. Compounding the issue, the plugin does not support distributed builds, meaning artifact uploads are performed from the Jenkins controller rather than from the build agent; this design flaw means a manipulated workspace directory path resolves to locations outside the intended restricted directory on the controller filesystem. An attacker with Item/Configure permission can craft a job configuration that specifies a traversal path (e.g., using ../ sequences) as the workspace directory, causing the plugin to read and upload files from arbitrary locations on the controller to Jira (Jenkins Advisory, GitHub Advisory).
Successful exploitation allows a low-privileged attacker (with Item/Configure permission) to read arbitrary files present on the Jenkins controller's workspace directory, potentially exposing sensitive configuration files, credentials, secrets, or other application data stored on the controller. There is no integrity or availability impact — the vulnerability is limited to confidentiality. However, access to sensitive files such as Jenkins configuration or credential stores could facilitate lateral movement or privilege escalation within the CI/CD environment (Jenkins Advisory).
../../etc/ or another sensitive path on the Jenkins controller filesystem).../ sequences.config.xml files on the Jenkins controller containing workspace directory values with path traversal patterns (e.g., ../../etc/passwd, ../../var/jenkins_home/secrets/).As of the advisory publication date (December 10, 2025), no patched version of the Redpen - Pipeline Reporter for Jira Plugin is available (Jenkins Advisory). Recommended mitigations include:
The vulnerability was discovered and reported by Yaroslav Afenkin of CloudBees, Inc., and was disclosed as part of the Jenkins December 10, 2025 security advisory alongside several other plugin and core vulnerabilities. No notable independent researcher commentary, social media discussion, or significant media coverage specific to CVE-2025-67643 has been identified beyond standard vulnerability database aggregation (Jenkins Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."