PT-2025-21239 · Jenkins · Jenkins Cadence Vmanager Plugin+1

Vincent Lardet

·

Published

2025-05-14

·

Updated

2025-06-12

·

CVE-2025-47886

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins Cadence vManager Plugin versions 4.0.1-286.v9e25a 740b a 48 and earlier
Description: A cross-site request forgery (CSRF) issue allows attackers to connect to an attacker-specified URL using an attacker-specified username and password. This can be exploited by attackers to perform unauthorized actions.
Recommendations: For Jenkins Cadence vManager Plugin versions 4.0.1-286.v9e25a 740b a 48 and earlier, consider disabling the plugin until a patch is available to prevent exploitation. Restrict access to sensitive URLs and credentials to minimize the risk of unauthorized connections.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-47886
GHSA-5W52-96JJ-FV59

Affected Products

Jenkins
Jenkins Cadence Vmanager Plugin