Jenkins
Jenkins Security Advisory 2025-01-22
2025-01-22 Jan 22, 2025 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2025-01-22/. 6 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2025-01-22/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
7 lines
Showing 1–7 of 7
CVE-2025-24399
BR2025-0000-009478
SECURITY-3461
unclaimed
Improper handling of case sensitivity in OpenId Connect Authentication Plugin
Credited as James Nord, CloudBees, Inc.
CVE-2025-24402
BR2025-0000-009479
SECURITY-3094
unclaimed
CSRF vulnerability and missing permission checks in Azure Service Fabric Plugin
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2025-24397
BR2025-0000-009480
SECURITY-3260
unclaimed
Incorrect permission check in GitLab Plugin allows enumerating credentials IDs
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2025-24397
BR2025-0000-009481
SECURITY-3260
unclaimed
Incorrect permission check in GitLab Plugin allows enumerating credentials IDs
Credited as Yaroslav Afenkin, CloudBees, Inc.
CVE-2025-24400
BR2025-0000-009482
SECURITY-3485
unclaimed
Cache confusion in Eiffel Broadcaster Plugin
Credited as Magnus Bäck, Axis Communications
CVE-2025-24398
BR2025-0000-009483
SECURITY-3434
unclaimed
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
Credited as Vincent Latombe, CloudBees, Inc.
CVE-2025-24401
BR2025-0000-009484
SECURITY-3062
unclaimed
Disabled permissions can be granted by Folder-based Authorization Strategy Plugin
Credited as Yaroslav Afenkin, CloudBees, Inc.