Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xv7v-hw45-9jgw

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

EPSS

Процентиль: 10%
0.002
Низкий

2.7 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.8
redhat
около 2 месяцев назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

CVSS3: 2.7
nvd
около 2 месяцев назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

EPSS

Процентиль: 10%
0.002
Низкий

2.7 Low

CVSS3

Дефекты

CWE-284