8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.
AI Analysis
Jervis library is vulnerable to Bleichenbacher padding oracle attacks due to the use of PKCS1Encoding prior to version 2.2.
Basic Information
ID
CVE-2025-68698
Source
GitHub_M
Published
Jan 13, 2026 at 19:16
Affected Product
Vendor
samrocketman
Product
jervis
Version
< 2.2
Affected Versions
samrocketman jervis < 2.2
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
samrocketman
Product
Jervis
Version
< 2.2