Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84646

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

A flaw was found in Jenkins. An attacker with Overall/Read permission can exploit a deserialization vulnerability where user objects can appear as nested field values in other deserialized XML objects. By submitting crafted XML, the attacker can create unauthorized user objects. While these created user objects are not actual Jenkins accounts and cannot be used for login, their unauthorized creation could lead to unexpected behavior or resource manipulation within the Jenkins environment.

Отчет

This Moderate impact flaw in Jenkins allows authenticated attackers with Overall/Read permission to create unauthorized user objects through crafted XML deserialization. While these objects do not grant login capabilities nor expose confidential information, their creation could lead to unexpected resource manipulation within the Jenkins environment.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the Jenkins instance to only trusted users and networks. Additionally, ensure that user permissions are configured with the principle of least privilege, limiting Overall/Read access to only those users who absolutely require it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2527599jenkins: Jenkins: Unauthorized creation of user objects via deserialization vulnerability

EPSS

Процентиль: 20%
0.00276
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
14 дней назад

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

CVSS3: 4.3
github
14 дней назад

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

EPSS

Процентиль: 20%
0.00276
Низкий

4.3 Medium

CVSS3