Описание
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
A flaw was found in Jenkins. An attacker with Overall/Read permission can exploit a deserialization vulnerability where user objects can appear as nested field values in other deserialized XML objects. By submitting crafted XML, the attacker can create unauthorized user objects. While these created user objects are not actual Jenkins accounts and cannot be used for login, their unauthorized creation could lead to unexpected behavior or resource manipulation within the Jenkins environment.
Отчет
This Moderate impact flaw in Jenkins allows authenticated attackers with Overall/Read permission to create unauthorized user objects through crafted XML deserialization. While these objects do not grant login capabilities nor expose confidential information, their creation could lead to unexpected resource manipulation within the Jenkins environment.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the Jenkins instance to only trusted users and networks. Additionally, ensure that user permissions are configured with the principle of least privilege, limiting Overall/Read access to only those users who absolutely require it.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
EPSS
4.3 Medium
CVSS3