PT-2026-88164 · Bitnami · Jenkins

Publicado

2026-09-08

·

Atualizado

2026-09-08

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In Stapler 2107.v8dfcb e8ed317 and earlier, except 2088.2093.vd7c3e58008a 6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BIT-JENKINS-2026-84647

Produtos afetados

Jenkins