Impact
The vulnerability arises from missing permission checks on Jenkins’ Appearance configuration page. Attackers who possess Overall/Manage rights can change configuration options that should be restricted, potentially altering the UI or plugin behavior in ways that were not intended. This flaw enables unauthorized modification of Jenkins settings, which can lead to information disclosure or additional privilege escalation if the altered settings expose sensitive data or weaken security controls.
Affected Systems
Affected systems include the Jenkins Project’s Jenkins server. The flaw impacts versions 2.421 through 2.579 (inclusive) and 2.426.1 through 2.568.2 (inclusive) within the LTS series.
Risk and Exploitability
The CVSS score is not provided, and EPSS data is unavailable, so precise quantitative risk is unknown. The flaw is listed as not included in CISA’s KEV catalog, indicating no confirmed public exploits at the time of this analysis. The attack vector requires an attacker to already have Overall/Manage permission, which could be acquired through another compromise or misconfiguration. Since the privilege escalation allows modification of Jenkins configuration, the potential impact is significant for environments where Jenkins settings control critical build pipelines or infrastructure. However, the lack of an external exploit and the prerequisite permission suggest a moderate to high risk contingent on the threat model.
OpenCVE Enrichment