Impact
Stapler, a core component of Jenkins, fails to limit the types of objects that can be created through form data binding. Attackers with Overall/Read permission can submit form data that causes Stapler to instantiate configuration classes not intended for that field type, potentially enabling unauthorized configuration changes or code execution if the chosen class performs privileged actions.
Affected Systems
All Jenkins installations up through 2.579 and the 2.568.2 LTS release that include Stapler 2107.v8dfcb_e8ed317 or earlier versions, except for the specific revision 2088.2093.vd7c3e58008a_6, are vulnerable. This applies to both standard and long‑term support releases.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1% suggests a low probability of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the required permission—Overall/Read—is commonly granted to many users, meaning that a legitimate or compromised user who can submit form data could exercise the flaw without elevated privileges. Exploitation would involve crafting a malicious form payload that directs Stapler to instantiate a chosen configuration class, potentially leading to unauthorized changes or code execution.
OpenCVE Enrichment