CyberRota Analysis
AI-GeneratedJenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable due to a flaw in the Remoting deserialization implementation, where the JEP-200 class filter is not enforced for classes resolved through fallback paths. This vulnerability allows agents and attackers with Agent/Connect permissions to bypass security measures, potentially leading to unauthorized code execution. Organizations using affected Jenkins versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.