MEDIUM 4.3 Maven
Jenkins is missing a permission check on password fields
GHSA-p3f5-98cv-562j · BIT-jenkins-2025-67636 · CVE-2025-67636
Published · Modified
Description
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
Ready to move
Start Securing
Free, no credit card | First findings in minutes