CVE 5.4 MEDIUM

CVE-2025-64132_CVE-2025-64132

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.

Basic Information

ID CVE-2025-64132
Source jenkins
Published Oct 29, 2025 at 13:29
Modified Oct 29, 2025 at 14:05

Affected Product

Vendor Jenkins Project
Product Jenkins MCP Server Plugin
Affected Versions Jenkins Project Jenkins MCP Server Plugin 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.