CVE-2026-27100

MEDIUM4.3EPSS 0.35%

Jenkins has a build information disclosure vulnerability through Run Parameter

發布日:2026/2/18修改日:2026/2/25
也稱為:GHSA-wfhp-qgm8-5p5cBIT-jenkins-2026-27100CGA-v589-93qp-5cvx

描述

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(6)