PT-2025-9861 · Jenkins+1 · Jenkins+1
Antoine Ruffino
·
Published
2025-03-05
·
Updated
2025-06-24
·
CVE-2025-27624
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.499 and earlier, LTS 2.492.1 and earlier
Description
A cross-site request forgery (CSRF) vulnerability allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets, such as Build Queue and Build Executor Status widgets. This issue arises because the HTTP endpoint for toggling the collapsed/expanded status does not require POST requests, making it vulnerable to CSRF attacks. Additionally, the API accepts any string as the identifier of the panel ID to be toggled, allowing attacker-controlled content to be stored in the victim's user profile in Jenkins.
Recommendations
For Jenkins versions 2.499 and earlier, update to version 2.500 or later to resolve the issue.
For LTS versions 2.492.1 and earlier, update to LTS version 2.492.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the affected HTTP endpoint until a patch is available.
Avoid using the vulnerable API endpoint for toggling sidepanel widgets until the issue is resolved.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Red Os