PT-2025-14510 · Jenkins+1 · Jenkins+1

Daniel Beck

·

Published

2025-04-02

·

Updated

2025-04-29

·

CVE-2025-31720

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.503 and earlier Jenkins LTS versions 2.492.2 and earlier
Description A missing permission check in Jenkins allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.
Recommendations For Jenkins versions 2.503 and earlier, update to a version that includes the fix for the missing permission check. For Jenkins LTS versions 2.492.2 and earlier, update to a version that includes the fix for the missing permission check. As a temporary workaround, consider restricting the Computer/Create permission to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03792
BIT-JENKINS-2025-31720
CVE-2025-31720
GHSA-565R-PF5Q-45V6

Affected Products

Jenkins
Red Os