Impact
The Jenkins Performance Plugin in versions 1015.v09ca_52b_3370e and earlier fails to restrict the classes that can be instantiated during deserialization of cached performance reports stored on the Jenkins controller. This flaw, a classic deserialization vulnerability (CWE‑502), permits an attacker who can configure a Jenkins item to execute arbitrary code on the controller.
Affected Systems
The affected component is the Jenkins Project Jenkins Performance Plugin, specifically versions 1015.v09ca_52b_3370e and earlier. The vulnerability is triggered by cached performance reports in the build directory of a Jenkins controller.
Risk and Exploitability
With a CVSS score of 8.8 the issue is considered high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to have Item/Configure permission, giving them the ability to run the deserialization code. Once the permitted user supplies a malicious payload, arbitrary code execution on the Jenkins controller follows, exposing the system to full compromise.
OpenCVE Enrichment