CVE-2025-67636: Medium severity Jenkins Jenkins vulnerability
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67636?
CVE-2025-67636 has been classified as a medium severity vulnerability due to the potential exposure of sensitive encrypted password values.
How do I fix CVE-2025-67636?
To fix CVE-2025-67636, upgrade Jenkins to version 2.541 or later, or LTS to version 2.528.3 or later.
Who is affected by CVE-2025-67636?
CVE-2025-67636 affects Jenkins versions up to 2.540 and Jenkins LTS versions up to 2.528.2.
What type of vulnerability is CVE-2025-67636?
CVE-2025-67636 is a vulnerability that involves a missing permission check allowing unauthorized access to encrypted data.
Can attackers exploit CVE-2025-67636 without authentication?
Attackers with only View/Read permissions can exploit CVE-2025-67636 to access encrypted passwords, but they still need authenticated access to the Jenkins instance.