Impact
The Jenkins Job Configuration History Plugin, in releases 1367.vc8fa_b_15101dc and earlier, contains a flaw that permits an attacker to overwrite the plugin’s history recording configuration via Stapler data binding. By sending specially crafted requests, an attacker can redirect history storage to a directory of their choice and alter settings that control how job histories are recorded. This results in unauthorized changes to the plugin’s behaviour, potentially tampering with audit logs and compromising the integrity of configuration history.
Affected Systems
The vulnerable component is the Jenkins Job Configuration History Plugin distributed by the Jenkins Project. Any Jenkins instance using a plugin version 1367.vc8fa_b_15101dc or older is impacted. No further version granularity is provided in the advisory.
Risk and Exploitability
The advisory does not publish a CVSS score, and EPSS is not available, so the exact severity and exploitation probability are not formally quantified. In the absence of an official patch, limiting write access to the plugin’s configuration files and enforcing a whitelist of allowable directories can mitigate the risk. Hardening Jenkins security by limiting exposure of Stapler endpoints and ensuring only authorized users can access the plugin configuration will reduce exploitation likelihood. The ability to redirect history storage suggests that in environments lacking stringent access controls, the potential impact on audit integrity can be significant. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment