CVE-2025-64140: OS Command Injection
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary shell commands.
Other sources
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller.
This allows attackers with Item/Configure permission to execute arbitrary shell commands on the Jenkins controller.
As of publication of this advisory, there is no fix.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64140?
CVE-2025-64140 has been classified as a critical vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2025-64140?
To fix CVE-2025-64140, upgrade to a version of the Jenkins Azure CLI Plugin later than 0.9.
What permissions are required to exploit CVE-2025-64140?
An attacker needs Item/Configure permission to exploit CVE-2025-64140 and execute arbitrary shell commands.
What version of Jenkins Azure CLI Plugin is affected by CVE-2025-64140?
Jenkins Azure CLI Plugin versions 0.9 and earlier are affected by CVE-2025-64140.
What can attackers achieve by exploiting CVE-2025-64140?
By exploiting CVE-2025-64140, attackers can execute arbitrary shell commands on the Jenkins controller.