PT-2025-5359 · Jenkins · Jenkins Folder-Based Authorization Strategy Plugin+1

Yaroslav Afenkin

·

Published

2025-01-22

·

Updated

2025-10-03

·

CVE-2025-24401

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Jenkins Folder-based Authorization Strategy Plugin versions 217.vd5b 18537403e and earlier
Description The issue potentially allows users who were formerly granted certain permissions to access functionality they are no longer entitled to, because the plugin does not verify that the configured permissions are enabled. This typically involves optional permissions.
Recommendations For Jenkins Folder-based Authorization Strategy Plugin versions 217.vd5b 18537403e and earlier, as a temporary workaround, consider reviewing and manually validating the permissions configured for each user to ensure they align with the intended access levels, until a patch is available.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-24401
GHSA-969G-RQ57-C79H

Affected Products

Jenkins
Jenkins Folder-Based Authorization Strategy Plugin