CVE 8.2 HIGH

Jervis has a Weak Random for Timing Attack Mitigation_CVE-2025-68704

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.

Basic Information

ID CVE-2025-68704
Source GitHub_M
Published Jan 13, 2026 at 19:29
Modified Jan 13, 2026 at 19:54

Affected Product

Vendor samrocketman
Product jervis
Version < 2.2
Affected Versions samrocketman jervis < 2.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.