Impact
Stapler, a key component of Jenkins, fails to restrict the types of objects that can be instantiated via form data binding. As a result, attackers with Overall/Read permission are able to create instances of arbitrary configuration classes that were not intended to be exposed. This can lead to unauthorized configuration changes or potential code execution if the instantiated classes contain malicious payloads.
Affected Systems
All Jenkins installations up through 2.579 and the 2.568.2 LTS release that include Stapler 2107.v8dfcb_e8ed317 or earlier versions, except for the specific revision 2088.2093.vd7c3e58008a_6, are vulnerable. This applies to both standard and long‑term support releases.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation data at this time. However, the required permission level—Overall/Read—is commonly granted to many users, meaning that an attacker who can submit form data to a Jenkins instance may exploit the flaw without needing elevated privileges. The attack would involve constructing a malicious form payload that directs Stapler to instantiate a chosen configuration class.
OpenCVE Enrichment