CyberRota Analysis
AI-GeneratedThe Jenkins TICS Plugin versions up to 2025.1.1 are vulnerable to an OS command injection flaw that enables attackers with control over build environment variables to execute arbitrary commands on the build agent. This vulnerability poses a significant risk, as it can lead to unauthorized access and manipulation of the system. Organizations using affected versions of Jenkins should prioritize patching this vulnerability to safeguard their build environments.
Original NVD Description
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.