Impact
A missing permission check in Jenkins up to version 2.579, including the LTS release 2.568.2, allows an attacker who has Item/Read permission on at least one job to read the names and values of build parameters for jobs they otherwise cannot access. This flaw does not provide control over the job itself but exposes potentially sensitive configuration data that could aid further attacks or reveal secrets embedded in build scripts. The weakness is classified as CWE‑862: Insecure Permissions.
Affected Systems
Jenkins, operated by the Jenkins Project, is affected. The vulnerability applies to all Jenkins installations running versions 2.579 or earlier, as well as the long‑term support build 2.568.2 and earlier. Any instance that has not been updated past these releases, regardless of additional plugins, remains susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, primarily affecting confidentiality. Because the attacker only needs at least one job with Item/Read permission, the practical attack vector is internal or privileged lateral movement within an organization’s Jenkins environment. EPSS data for this vulnerability is not available, and it is not listed in the CISA KEV catalogue, suggesting no widespread exploitation to date. Nevertheless, the low barrier to access and the exposure of parameter values warrant timely remediation.
OpenCVE Enrichment