PT-2026-2556 · Cloudbees+1 · Jenkins+1

CVE-2025-68925

·

Publicado

2026-01-13

·

Atualizado

2026-01-13

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jervis versions prior to 2.2
Description The Jervis library, used for Job DSL plugin scripts and shared Jenkins pipeline libraries, does not validate the algorithm specified in the JWT header, specifically checking for "alg":"RS256". This could potentially allow for unauthorized access or manipulation of Jenkins pipelines.
Recommendations Update Jervis to version 2.2 or later.

Exploit

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68925
GHSA-5PQ9-5MPR-JJ85

Produtos afetados

Jenkins
Jervis