Database/Control plane, storage & DevOps

Jenkins Entra ID plugin: a colliding Entra group display name inherits a privileged group's permissions
Impact
The plugin grants Entra group permissions on both the group's unique object ID and its display name, so a group created with a name matching a privileged one picks up that group's Jenkins authorization. Where administrator rights are granted to a group - the normal pattern with SSO-backed Jenkins - this is escalation to Jenkins administrator, and from there the Script Console and arbitrary code on the controller. A GPU shop's Jenkins controller typically holds registry push credentials, cluster kubeconfigs and cloud keys, so controller takeover is a direct path into the image supply chain feeding every GPU node. The precondition sits in the directory rather than in Jenkins: the attacker needs to create an Entra group in the linked tenant, which many organizations delegate widely.
Who can reach it
Remote authenticated Jenkins user with low privileges (CVSS PR:L) who can also create a group in the Entra tenant Jenkins authenticates against. No Jenkins administrator rights and no user interaction.
What to do
Upgrade the Microsoft Entra ID plugin past 710.v0b_ff8e9cc2d2 per SECURITY-3935 in the 2026-09-02 Jenkins advisory; the advisory marks that release and earlier as affected and does not name a fixed version number here, so take the current plugin release. Loading the new plugin costs a controller restart - the queue pauses and agents reconnect, running builds are lost unless drained first. As an interim control, review who can create groups in the Entra tenant and audit the Jenkins authorization matrix for group entries carrying administrator permissions.
References
Related entries
- KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes APINCVD-2026-051-kubeedge-configupdatejob-handler · KubeEdge (ConfigUpdateJob handler, updateFields)High
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheNCVD-2026-052-kubeedge-nodeupgradejob-handler · KubeEdge (NodeUpgradeJob handler, v1alpha2 API)High
- APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webCVE-2024-58310 · APC Network Management Card 4 (NMC4)High
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysCVE-2025-20163 · Cisco Nexus Dashboard Fabric Controller (SSH host key validation)High
- MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowingCVE-2025-31489 · MinIO (S3 API, unsigned-trailer uploads)High
- HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actionsCVE-2025-37101 · HPE OneView for VMware vCenter (vertical privilege escalation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.