← Back

CVE-2026-70430

nvd nist
Published: Aug 5, 2026Modified: Sep 8, 2026

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.2 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

Affected (2)

Products: Jenkins: Jenkins
1 product
Jenkins
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Jenkins
Before 2.576
Before 2.568.2

References (1)

Source: jenkinsci-cert@googlegroups.com
Vendor Advisory

Timeline

No history available yet.