Impact
In Jenkins 2.579 and earlier, and LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration allow an attacker to submit an XML document that specifies the name of a different agent. This overwrites that agent’s configuration, giving the attacker control over its inbound secret and environment variables. The flaw is a classic access control violation (CWE‑284). Based on the description, it is inferred that remote code execution could be possible if the attacker leverages the compromised agent configuration to execute arbitrary code on that agent.
Affected Systems
The Jenkins Project’s Jenkins product is affected. The vulnerability applies to Jenkins core versions 2.579 and earlier, and the long‑term support release 2.568.2 and earlier.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate to high severity. No EPSS score is available, but the flaw can be exploited remotely via the REST API or CLI by any user with Agent/Configure permission on at least one agent. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited, yet organizations that assign broad Agent/Configure rights face a significant risk of credential compromise and agent takeover.
OpenCVE Enrichment