PT-2026-2497 · Cloudbees+1 · Jenkins+1

CVE-2025-68704

·

Publicado

2026-01-13

·

Atualizado

2026-01-13

CVSS v4.0

8.2

Alta

VetorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jervis versions prior to 2.2
Description Jervis, a library for Job DSL plugin scripts and shared Jenkins pipeline libraries, utilizes java.util.Random(), which is not cryptographically secure and may be susceptible to timing attacks. This impacts the security of random number generation within the library.
Recommendations Update to version 2.2 or later.

Exploit

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68704
GHSA-C9Q6-G3HR-8GWW

Produtos afetados

Jenkins
Jervis