CyberRota Analysis
AI-GeneratedJenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable to an XML deserialization flaw that allows attackers with Overall/Read permissions to manipulate user objects by submitting specially crafted XML. This could lead to unauthorized user creation and potential escalation of privileges within the Jenkins environment. Organizations using affected versions of Jenkins should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
Related CVEs
Other vulnerabilities affecting the same vendor(s)