PT-2026-2496 · Cloudbees+1 · Jenkins+1

CVE-2025-68703

·

Publicado

2026-01-13

·

Atualizado

2026-01-13

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jervis versions prior to 2.2
Description Jervis, a library for Job DSL plugin scripts and shared Jenkins pipeline libraries, is affected by an issue where the salt used in encryption is derived from the SHA256 sum of the passphrase. This means that using the same password for two encryption operations will result in the same derived key.
Recommendations Update to version 2.2 or later.

Exploit

Correção

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68703
GHSA-36H5-VRQ6-PP34

Produtos afetados

Jenkins
Jervis