CVE-2025-31721
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.
Vendor
Product
CWE
Yayın Tarihi
2025-04-02 15:15:59
Güncelleme
2025-04-29 13:56:43
Source Identifier
jenkinsci-cert@googlegroups.com
KEV Date Added
-