CVE-2025-59474: Medium severity Jenkins Jenkins vulnerability
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.
Other sources
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission.
This allows attackers without Overall/Read permission to list agent names through its sidepanel executors widget.
Jenkins 2.528, LTS 2.516.3 removes the sidepanel from the affected view.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59474?
CVE-2025-59474 is considered a medium severity vulnerability due to improper permission checks in Jenkins.
How do I fix CVE-2025-59474?
To fix CVE-2025-59474, upgrade Jenkins to version 2.528 or LTS 2.516.3 or later.
What does CVE-2025-59474 affect?
CVE-2025-59474 affects Jenkins versions up to 2.527 and LTS versions up to 2.516.2.
Who can exploit CVE-2025-59474?
Attackers without Overall/Read permission can exploit CVE-2025-59474 to list agent names.
What is the main vulnerability in CVE-2025-59474?
The main vulnerability in CVE-2025-59474 is the lack of permission checks in the sidepanel of Jenkins pages.