PT-2025-50355 · Cloudbees+2 · Jenkins+1

James Nord

·

Published

2025-12-10

·

Updated

2025-12-23

·

CVE-2025-67637

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.540 and earlier Jenkins LTS versions 2.528.2 and earlier
Description Jenkins stores build authorization tokens unencrypted in config.xml files on the Jenkins controller. This allows users with Item/Extended Read permission, or access to the Jenkins controller file system, to view these tokens.
Recommendations Update Jenkins to a version later than 2.540. Update Jenkins LTS to a version later than 2.528.2.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-15960
BIT-JENKINS-2025-67637
CVE-2025-67637
GHSA-FXJ7-6V9W-XC76

Affected Products

Jenkins
Red Os