Impact
Jenkins versions 2.575 and earlier, together with the LTS releases 2.568.1 and earlier, allow the creation of project naming strategy configuration objects without restricting the constructor parameters. An attacker who already holds Overall or Manage permissions can instantiate arbitrary types—including those reserved for administrators—for configuration. This flaw is rooted in Improper Access Control (CWE‑284) and Deserialization of Untrusted Data (CWE‑502), and it enables unauthorized alteration of Jenkins behavior by injecting configuration changes normally protected for administrators.
Affected Systems
The vulnerability affects all installations of Jenkins up to and including release 2.575 and the Long‑Term Support release 2.568.1, regardless of the underlying operating system, when project naming strategies can be configured via the web UI, REST API, or configuration files.
Risk and Exploitability
The CVSS score is 2.7 and the EPSS score is less than 1 %. The flaw is not listed in the CISA KEV catalog, indicating no public exploits are currently known. Exploitation requires a user account with Overall or Manage rights; therefore the risk appears confined to scenarios in which such a privileged account is compromised or misused. While the overall likelihood of exploitation is low, a successful attack results in unauthorized configuration changes that could lead to resource mismanagement or other indirect impacts.
OpenCVE Enrichment