Impact
Jenkins versions 2.579 and earlier, including LTS 2.568.2 and earlier, contain a deserialization flaw where transient fields in configuration updates cannot be excluded. This allows an attacker who can submit or modify configuration data to inject values into transient fields that will be deserialized by the system. Depending on how these fields are subsequently used within Jenkins, the attacker could potentially influence configuration behavior or create a more severe issue such as command execution or corruption of internal state.
Affected Systems
The vulnerability affects Jenkins Project Jenkins. It is present in all Jenkins releases up to and including 2.579 and 2.568.2; newer releases are not impacted as they have been patched after the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS data is not available, but the fact that the flaw can be triggered via configuration updates that many users can submit suggests a realistic risk of exploitation, especially if privileged configuration access is open to untrusted users. The vulnerability is not listed in CISA KEV, yet the high CVSS and the potential impact on configuration integrity make it a priority for remediation. The likely attack vector is remote through Jenkins’ web interface, inferred from the ability to submit configuration updates over HTTP/HTTPS.
OpenCVE Enrichment