Impact
Jenkins has a flaw that lets users with read access craft XML to forge arbitrary user objects. The resulting accounts are fully authenticated and can be used to access protected resources. This breaks the integrity of the authentication system and may enable further privilege escalation.
Affected Systems
The vulnerability affects Jenkins Project implementations, including Jenkins 2.579 and any earlier releases, as well as the LTS 2.568.2 build and earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not provided. The flaw is not listed in the CISA KEV catalog. Attackors must hold Overall/Read permissions to submit malicious XML. Once exploited, they can create new user accounts, potentially bypassing existing security controls. The likelihood depends on the presence of users with such permissions and on the openness of XML handling interfaces.
OpenCVE Enrichment