CVE-2025-67643 Overview
CVE-2025-67643 is a path traversal vulnerability [CWE-22] in the Jenkins Redpen - Pipeline Reporter for Jira Plugin. Versions 1.054.v7b_9517b_6b_202 and earlier fail to correctly validate the workspace directory path when uploading artifacts to Jira. Attackers with Item/Configure permission can leverage this weakness to retrieve files from the Jenkins controller workspace directory. The issue affects a plugin commonly deployed in continuous integration environments that integrate Jenkins pipelines with Atlassian Jira for reporting.
Critical Impact
Authenticated attackers with configure permissions can read files from the Jenkins controller workspace, potentially exposing build artifacts, source code, and configuration data.
Affected Products
- Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier
- Jenkins controllers with the plugin installed and Jira integration enabled
- CI/CD pipelines relying on the plugin for artifact reporting
Discovery Timeline
- 2025-12-10 - Jenkins publishes security advisory SECURITY-3290
- 2025-12-10 - CVE-2025-67643 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-67643
Vulnerability Analysis
The flaw resides in the artifact upload logic of the Redpen - Pipeline Reporter for Jira Plugin. When the plugin prepares files for transmission to Jira, it accepts a workspace-relative path as input. The plugin does not enforce that the resolved path remains within the intended workspace directory. This allows an attacker to supply path segments such as .. to traverse outside the workspace boundary. Files elsewhere on the Jenkins controller filesystem can be read and exfiltrated through the legitimate artifact upload channel to Jira.
Exploitation requires an authenticated user account with Item/Configure permission on a Jenkins job. This precondition limits the attack surface to internal or partially trusted users. However, in shared Jenkins environments where developers hold configure rights on their own jobs, the vulnerability enables lateral information disclosure across projects.
Root Cause
The root cause is missing path canonicalization and boundary validation before file access. The plugin trusts the supplied path without verifying that its canonical form remains a descendant of the workspace root. This is a classic [CWE-22] Improper Limitation of a Pathname to a Restricted Directory weakness.
Attack Vector
An attacker with Item/Configure permission modifies a job configuration to reference a traversal path in the artifact upload step. On the next pipeline execution, the plugin resolves the path outside the workspace and uploads the targeted file to a Jira instance controlled by the attacker or otherwise accessible to them. See the Jenkins Security Advisory 2025-12-10 for the vendor description.
Detection Methods for CVE-2025-67643
Indicators of Compromise
- Job configuration changes that introduce .. sequences or absolute paths in artifact upload parameters for the Redpen plugin
- Unexpected Jira attachments containing Jenkins system files, credentials.xml, config.xml, or SSH keys
- Artifact uploads referencing paths outside the standard workspace/ directory tree
Detection Strategies
- Audit Jenkins job configuration history for modifications to Redpen plugin steps that specify non-standard file paths
- Correlate Jenkins audit logs with Jira attachment upload events to identify anomalous artifact contents
- Review use of the Item/Configure permission and enumerate accounts holding it across the controller
Monitoring Recommendations
- Enable and centrally collect the Jenkins Audit Trail Plugin logs for job configuration changes
- Alert on Jira attachments from Jenkins integrations that contain sensitive filename patterns such as id_rsa, .env, or credentials
- Track plugin version inventory across Jenkins controllers to identify unpatched instances
How to Mitigate CVE-2025-67643
Immediate Actions Required
- Inventory all Jenkins controllers and identify installations of the Redpen - Pipeline Reporter for Jira Plugin at version 1.054.v7b_9517b_6b_202 or earlier
- Restrict the Item/Configure permission to trusted users following the principle of least privilege
- Review recent Jira attachments originating from Jenkins for signs of unauthorized file exfiltration
Patch Information
Refer to the Jenkins Security Advisory 2025-12-10 for the fixed plugin version and upgrade instructions. Apply the vendor-supplied update through the Jenkins Plugin Manager once identified in your environment.
Workarounds
- Disable the Redpen - Pipeline Reporter for Jira Plugin until the patched version can be deployed
- Remove Item/Configure permission from untrusted users on affected controllers
- Isolate Jenkins controllers so that sensitive files reside outside job workspace parent directories where feasible
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.