Impact
The Jenkins Microsoft Entra ID plugin, version 710.v0b_ff8e9cc2d2 and earlier, assigns group permissions using both a group's unique object ID and its display name. An attacker who can create a new Entra group whose display name collides with that of a privileged group will be granted the permissions associated with the privileged group. This flaw enables an attacker to obtain elevated rights within the Jenkins instance without needing the original group's object ID.
Affected Systems
All Jenkins installations that deploy the Microsoft Entra ID (Azure AD) plugin at or before the affected version are impacted. The vulnerability exists wherever the plugin is used to map Entra group permissions, regardless of the Jenkins version itself.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity vulnerability. Although the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the nature of the flaw – granting privileged permissions through a name collision – indicates a potentially high impact if exploited. Likely attack conditions include an attacker having permission to create Entra groups and access the Jenkins plugin endpoint. While no active exploits are documented, the high CVSS suggests that the risk remains significant until a patch is applied.
OpenCVE Enrichment