Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Maven

Jenkins is missing a permission check on password fields

GHSA-p3f5-98cv-562j · BIT-jenkins-2025-67636 · CVE-2025-67636

Published · Modified

Description

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

Ready to move

Start Securing

Free, no credit card | First findings in minutes