PT-2026-2556 · Cloudbees+1 · Jenkins+1
CVE-2025-68925
·
Publicado
2026-01-13
·
Atualizado
2026-01-13
CVSS v4.0
6.9
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Jervis versions prior to 2.2
Description
The Jervis library, used for Job DSL plugin scripts and shared Jenkins pipeline libraries, does not validate the algorithm specified in the JWT header, specifically checking for "alg":"RS256". This could potentially allow for unauthorized access or manipulation of Jenkins pipelines.
Recommendations
Update Jervis to version 2.2 or later.
Exploit
Correção
Improper Verification of Cryptographic Signature
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jervis