CVE-2025-67639
- EPSS -
- Veröffentlicht 10.12.2025 16:50:38
- Zuletzt bearbeitet 10.12.2025 18:16:23
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.
CVE-2025-67638
- EPSS -
- Veröffentlicht 10.12.2025 16:50:37
- Zuletzt bearbeitet 10.12.2025 18:16:22
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
CVE-2025-67636
- EPSS -
- Veröffentlicht 10.12.2025 16:50:36
- Zuletzt bearbeitet 10.12.2025 18:16:22
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
CVE-2025-67637
- EPSS -
- Veröffentlicht 10.12.2025 16:50:36
- Zuletzt bearbeitet 10.12.2025 18:16:22
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controlle...
CVE-2025-67635
- EPSS -
- Veröffentlicht 10.12.2025 16:50:35
- Zuletzt bearbeitet 10.12.2025 18:16:21
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
CVE-2025-59476
- EPSS 0.09%
- Veröffentlicht 17.09.2025 13:17:48
- Zuletzt bearbeitet 04.11.2025 22:16:35
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters...
CVE-2025-59474
- EPSS 0.26%
- Veröffentlicht 17.09.2025 13:17:47
- Zuletzt bearbeitet 04.11.2025 22:16:35
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent name...
CVE-2025-59475
- EPSS 0.03%
- Veröffentlicht 17.09.2025 13:17:47
- Zuletzt bearbeitet 04.11.2025 22:16:35
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration ...
CVE-2024-9453
- EPSS 0.04%
- Veröffentlicht 04.07.2025 08:36:35
- Zuletzt bearbeitet 18.08.2025 19:02:46
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a mal...
CVE-2025-31720
- EPSS 0.03%
- Veröffentlicht 02.04.2025 15:15:59
- Zuletzt bearbeitet 29.04.2025 14:03:21
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.