Impact
The Jenkins LDAP Plugin up to version 807.809 allows an attacker to supply a URL that the plugin will connect to through Stapler data binding. This enables the plugin to reach arbitrary network addresses, potentially exposing internal services or data to external actors. Although the disclosed impact is limited to outbound connections, the ability to reach internal network resources can facilitate further attacks such as data exfiltration or internal reconnaissance. The vulnerability is categorized as CWE‑601, reflecting the unsafe handling of external URLs.
Affected Systems
The affected component is the Jenkins LDAP Plugin distributed by the Jenkins Project. All releases of the plugin identified as 807.809.vd3a_4e5e4ec98 and earlier are vulnerable. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate severity. An exploitation would require network access to the Jenkins server and the ability to submit configuration data to the plugin. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Given the absence of a known public exploit and the moderate score, the threat is considered low to moderate, but monitoring for anomalous outbound traffic is advisable.
OpenCVE Enrichment