Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-70430

Опубликовано: 05 авг. 2026
Источник: nvd
CVSS3: 2.7
EPSS Низкий

Описание

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 2.568.2 (исключая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
Версия до 2.576 (исключая)

EPSS

Процентиль: 10%
0.002
Низкий

2.7 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.8
redhat
около 2 месяцев назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

CVSS3: 2.7
github
около 2 месяцев назад

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.

EPSS

Процентиль: 10%
0.002
Низкий

2.7 Low

CVSS3

Дефекты

CWE-284