CVE-2025-31721
02.04.2025, 15:15
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 < 2.492.3 |
jenkins | jenkins | 𝑥 < 2.504 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration