Impact
Jenkins 2.575 and earlier, as well as LTS 2.568.1 and earlier, handle case‑insensitive user and group names inconsistently. This flaw, identified as a weakness in authentication and authorization (CWE-178), allows an attacker who can create a new user or group to choose a name that, when case‑insensitively matched, may correspond to an existing account. The attacker can thereby impersonate that user or inherit the user’s permissions in certain contexts, enabling unauthorized access to build pipelines, configuration, or administrative functions.
Affected Systems
The Jenkins Project’s Jenkins product is affected; versions 2.575 and earlier, and Long‑Term Support 2.568.1 and earlier, contain the vulnerability.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% reflects a very low but nonzero probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need the ability to create or modify user or group accounts, which can be achieved through the web interface, REST API, or command-line tools. This suggests the attack vector is remote, requiring either unauthenticated or minimally authenticated access to the Jenkins instance. No evidence of remote code execution or other advanced exploits is provided.
OpenCVE Enrichment