4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Basic Information
ID
CVE-2025-67637
Source
jenkins
Published
Dec 10, 2025 at 16:50
Modified
Dec 10, 2025 at 17:33
Affected Product
Vendor
Jenkins Project
Product
Jenkins
Version
2.541