PT-2025-35781 · Jenkins · Jenkins Global-Build-Stats Plugin+1
Daniel Beck
·
Published
2025-09-03
·
Updated
2025-09-08
·
CVE-2025-58459
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins global-build-stats Plugin versions 322.v22f4db 18e2dd and earlier
Description
The Jenkins global-build-stats Plugin does not perform permission checks in its REST API endpoints. Attackers with Overall/Read permission can enumerate graph IDs.
Recommendations
Update to a version later than 322.v22f4db 18e2dd.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Global-Build-Stats Plugin