8.2
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.
Basic Information
ID
CVE-2025-68704
Source
GitHub_M
Published
Jan 13, 2026 at 19:29
Modified
Jan 13, 2026 at 19:54
Affected Product
Vendor
samrocketman
Product
jervis
Version
< 2.2
Affected Versions
samrocketman jervis < 2.2