First published: Wed Jan 22 2025(Updated: )
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Folder-based Authorization Strategy Plugin | <217.vd5b_18537403e | |
maven/io.jenkins.plugins:folder-auth | <=217.vd5b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24401 has been classified as a potentially high-severity vulnerability.
To mitigate CVE-2025-24401, upgrade the Jenkins Folder-based Authorization Strategy Plugin to version 217.vd5b_18537403f or later.
Organizations using Jenkins Folder-based Authorization Strategy Plugin version 217.vd5b_18537403e and earlier are affected by CVE-2025-24401.
CVE-2025-24401 may allow unauthorized access to Jenkins functionality by users who should no longer have those permissions.
Versions of the Jenkins Folder-based Authorization Strategy Plugin up to and including 217.vd5b_18537403e are impacted by CVE-2025-24401.