CVE-2025-67635
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
Vendor
Product
CWE
Yayın Tarihi
2025-12-10 17:15:55
Güncelleme
2025-12-17 17:39:45
Source Identifier
jenkinsci-cert@googlegroups.com
KEV Date Added
-