CVE-2025-31721
EUVD-2025-952602.04.2025, 15:15
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | jenkins | 𝑥 < 2.492.3 |
| jenkins | jenkins | 𝑥 < 2.504 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration