CVE-2025-31720

MEDIUM4.3EPSS 0.09%

Jenkins Missing Permission Check

發布日:2025/4/2修改日:2026/2/4
也稱為:GHSA-565r-pf5q-45v6BIT-jenkins-2025-31720CGA-24wx-77wg-h76x

描述

Jenkins 2.503 and earlier, LTS 2.492.2 and earlier does not perform a permission check in an HTTP endpoint. This allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration. Jenkins 2.504, LTS 2.492.3 requires Computer/Extended Read permission to copy an agent.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

參考連結(3)