Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2xq-2v27-4rh3

Опубликовано: 10 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled config.xml submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled config.xml submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

EPSS

Процентиль: 97%
0.19035
Средний

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
redhat
около 2 месяцев назад

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

CVSS3: 8.8
nvd
около 2 месяцев назад

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

CVSS3: 8.8
fstec
около 2 месяцев назад

Уязвимость библиотеки XStream сервера автоматизации Jenkins, позволяющая нарушителю осуществить подмену HTTP-запросов, получить несанкционированный доступ к Script Console и выполнить произвольный код или раскрыть защищаемую информацию

EPSS

Процентиль: 97%
0.19035
Средний

8.8 High

CVSS3

Дефекты

CWE-502