VYPR
Moderate severityOSV Advisory· Published Dec 10, 2025· Updated Dec 10, 2025

CVE-2025-67636

CVE-2025-67636

Description

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.main:jenkins-coreMaven
>= 2.529, < 2.5412.541
org.jenkins-ci.main:jenkins-coreMaven
< 2.528.32.528.3

Affected products

4

Patches

Vulnerability mechanics

References

4

News mentions

1