CyberRota Analysis
AI-GeneratedJenkins versions 2.575 and earlier, as well as LTS 2.568.1 and earlier, are vulnerable due to insufficient restrictions on object instantiation within project naming strategy configurations. This flaw enables attackers with Overall/Manage permissions to create arbitrary configuration types, potentially compromising the integrity of the Jenkins environment. Organizations using these affected versions should prioritize patching to mitigate risks associated with unauthorized configuration changes.
Original NVD Description
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.