PT-2025-44284 · Jenkins · Jenkins Eggplant Runner Plugin+1

Pierre Beitz

·

Published

2025-10-29

·

Updated

2025-12-22

·

CVE-2025-64135

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Eggplant Runner Plugin versions 0.0.1.301.v963cffe8ddb 8 and earlier
Description The Jenkins Eggplant Runner Plugin versions 0.0.1.301.v963cffe8ddb 8 and earlier configures the Java system property jdk.http.auth.tunneling.disabledSchemes to an empty value. This action disables a security feature within the Java runtime environment, potentially weakening protection mechanisms.
Recommendations Update to a newer version of the Jenkins Eggplant Runner Plugin.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-64135
GHSA-W5R3-GR8W-7FJ5

Affected Products

Jenkins
Jenkins Eggplant Runner Plugin