Impact
The vulnerability in the Jenkins XML Job to Job DSL Plugin allows a user without proper permissions to invoke the conversion functionality. This represents an improper authorization failure, allowing unauthorized modification or creation of job definitions within the Jenkins instance. The issue is identified as a permission check omission (CWE‑862).
Affected Systems
Jenkins installations that include the XML Job to Job DSL Plugin version 0.1.13 or earlier are affected. Application of the plugin beyond this version is not known to be impacted by this issue.
Risk and Exploitability
Based on the description, it is inferred that attackers can trigger the conversion endpoint remotely via HTTP/HTTPS requests if they can reach the Jenkins server. The CVSS score of 6.5 indicates medium severity; the EPSS score is not listed. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation at present. Still, the capability to alter job configurations without authorization represents a significant security risk for exposed Jenkins instances.
OpenCVE Enrichment