Impact
The Jenkins Script Security Plugin, in versions 1412.v7737b_3405f86 and earlier, applies the @DataBoundConstructor annotation to a constructor that loads the script approval configuration. This oversight allows an attacker who can submit certain forms to read the configuration data, potentially exposing privileged script approval details. The flaw is documented as CWE-200, Information Exposure by External Control of System or Application.
Affected Systems
This vulnerability affects the Jenkins Project Jenkins Script Security Plugin. The vulnerability description does not specify affected versions; all currently available releases may be impacted until a fix is released.
Risk and Exploitability
The CVSS score for this vulnerability is 4.3, indicating moderate risk. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. It is likely exploitable through web form submissions within a Jenkins instance, implying a local or web-based attack vector. The attacker would need to supply crafted form input to trigger the constructor and obtain configuration details.
OpenCVE Enrichment