CVE-2025-67638: Medium severity Jenkins Jenkins vulnerability
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67638?
CVE-2025-67638 is categorized as a high-severity vulnerability due to its potential for unauthorized token disclosure.
How do I fix CVE-2025-67638?
To fix CVE-2025-67638, upgrade Jenkins to version 2.541 or later, or LTS 2.528.3 or later.
What happens if I don't address CVE-2025-67638?
Failing to address CVE-2025-67638 may allow attackers to capture sensitive build authorization tokens, leading to unauthorized access.
What versions of Jenkins are affected by CVE-2025-67638?
Jenkins versions 2.540 and earlier, and LTS versions 2.528.2 and earlier are affected by CVE-2025-67638.
Is there a workaround for CVE-2025-67638 until I can upgrade?
Currently, there are no documented workarounds for CVE-2025-67638, so upgrading is the recommended action.