6.5
CVE-2026-42521
- EPSS 0.25%
- Veröffentlicht 29.04.2026 14:16:19
- Zuletzt bearbeitet 06.05.2026 16:21:01
- Erkennungen
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impacts depending on the classes available on the classpath.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Matrix Authorization Strategy SwPlatform jenkins Version >= 2.1 < 3.2.10
Jenkins ≫ Matrix Authorization Strategy Version 2.0 Update beta1 SwPlatform jenkins
Jenkins ≫ Matrix Authorization Strategy Version 2.0 Update beta2 SwPlatform jenkins
Jenkins ≫ Matrix Authorization Strategy Version 2.0 Update beta3 SwPlatform jenkins
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.155 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://www.jenkins.io/security/advisory/2026-04-29/#SECURITY-3676