PT-2026-84798 · Jenkins · Jenkins Metrics Plugin

CVE-2026-84675

·

Publicado

2026-09-02

·

Atualizado

2026-09-02

CVSS v3.1

7.4

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-84675

Produtos afetados

Jenkins Metrics Plugin