Количество 5
Количество 5
CVE-2025-59475
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).
CVE-2025-59475
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).
GHSA-223m-4rfp-646h
Jenkins is missing a permission check in the authenticated users' profile menu
BDU:2025-13362
Уязвимость сервера автоматизации Jenkins, позволяющая нарушителю получить несанкционированный доступ к функциям, которые в противном случае были бы ограничены
ROS-20251022-02
Множественные уязвимости jenkins
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-59475 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed). | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-59475 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed). | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-223m-4rfp-646h Jenkins is missing a permission check in the authenticated users' profile menu | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
BDU:2025-13362 Уязвимость сервера автоматизации Jenkins, позволяющая нарушителю получить несанкционированный доступ к функциям, которые в противном случае были бы ограничены | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
ROS-20251022-02 Множественные уязвимости jenkins | CVSS3: 5.3 | 13 дней назад |
Уязвимостей на страницу