important · Automation
Delegated Jenkins configuration access can reach controller-side script execution.
Affects
Jenkins, a Java-based automation and continuous-integration controller commonly entrusted with build credentials and artifact production.
A crafted config.xml can deserialize a nested PersistenceRoot object, expose its Stapler routes and reach the improperly protected Script Console in the controller process.
Detail and 1 source
Jenkins published fixed releases, and no public exploit code was located by the cutoff.