Количество 2
Количество 2
CVE-2025-68931
26 дней назад
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.
CVSS3: 7.5
EPSS: Низкий
GHSA-gxp5-mv27-vjcj
26 дней назад
Jervis's AES CBC Mode is Without Authentication
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-68931 Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2. | CVSS3: 7.5 | 0% Низкий | 26 дней назад | |
GHSA-gxp5-mv27-vjcj Jervis's AES CBC Mode is Without Authentication | CVSS3: 7.5 | 0% Низкий | 26 дней назад |
Уязвимостей на страницу
20