Low severityOSV Advisory· Published Dec 10, 2025· Updated Dec 10, 2025
CVE-2025-67639
CVE-2025-67639
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | >= 2.529, < 2.541 | 2.541 |
org.jenkins-ci.main:jenkins-coreMaven | < 2.528.3 | 2.528.3 |
Affected products
4- Range: 1.324-rc, 1.325-rc, 1.327-rc, …
- osv-coords3 versions
< 2.528.3-r2+ 2 more
- (no CPE)range: < 2.528.3-r2
- (no CPE)range: < 2.528.3
- (no CPE)range: >= 2.529, < 2.541
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-6837-qgrc-x5p6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-67639ghsaADVISORY
- www.jenkins.io/security/advisory/2025-12-10/ghsavendor-advisoryWEB
- github.com/jenkinsci/jenkins/commit/31598feb0aa514d8978d2c27a4c9a5a9b8d80a57ghsaWEB
News mentions
1- Jenkins Security Advisory 2025-12-10Jenkins Security Advisories · Dec 10, 2025