CVE 8.7 HIGH

Jervis has an RSA PKCS#1 v1.5 Padding Vulnerability_CVE-2025-68698

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.

AI Analysis

Jervis library is vulnerable to Bleichenbacher padding oracle attacks due to the use of PKCS1Encoding prior to version 2.2.

Basic Information

ID CVE-2025-68698
Source GitHub_M
Published Jan 13, 2026 at 19:16

Affected Product

Vendor samrocketman
Product jervis
Version < 2.2
Affected Versions samrocketman jervis < 2.2

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor samrocketman
Product Jervis
Version < 2.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.