GHSA-pvwx-3jx5-24r2
GitHub Security Advisory
Lack of type validation in agent related REST API in Jenkins
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node.
This allows attackers with Computer/Configure permission to replace a node with one of a different type.
Jenkins 2.287, LTS 2.277.2 validates the type of object created and rejects objects of unexpected types.
Affected Packages
Maven
org.jenkins-ci.main:jenkins-core
Affected versions:
0
(fixed in 2.277.2)
Maven
org.jenkins-ci.main:jenkins-core
Affected versions:
2.278
(fixed in 2.287)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.