PT-2026-35915 · Jenkins · Matrix Authorization Strategy Plugin
Arafat Ul Islam
+1
·
Published
2026-04-29
·
Updated
2026-04-29
·
CVE-2026-42521
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Matrix Authorization Strategy Plugin versions 2.0-beta-1 through 3.2.9
Description
The plugin invokes parameterless constructors of classes specified in the configuration during the deserialization of inheritance strategies. Because it does not restrict the classes that can be instantiated, users with Item/Configure permission can instantiate arbitrary types. This may result in information disclosure or other impacts depending on the classes available on the classpath.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix Authorization Strategy Plugin