PT-2026-2493 · Jervis · Jervis

Published

2026-01-13

·

Updated

2026-01-13

·

CVE-2025-68698

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jervis versions prior to 2.2
Description Jervis, a library for Job DSL plugin scripts and shared Jenkins pipeline libraries, utilizes PKCS1Encoding, which is susceptible to Bleichenbacher padding oracle attacks. Modern systems should employ OAEP (Optimal Asymmetric Encryption Padding) for enhanced security. This issue has been addressed in version 2.2. A Bleichenbacher padding oracle attack exploits weaknesses in the PKCS#1 v1.5 padding scheme used in certain cryptographic algorithms.
Recommendations Update Jervis to version 2.2 or later.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-68698
GHSA-MQW7-C5GG-XQ97

Affected Products

Jervis