Permission Check Flaw in Jenkins Affects User Data Access
CVE-2025-59474
Currently unrated
What is CVE-2025-59474?
A significant vulnerability has been identified in Jenkins that fails to enforce proper permission checks for users lacking Overall/Read permissions. Specifically, those who do not possess the necessary permissions can exploit this flaw to access and enumerate agent names through the sidepanel executors widget, thereby exposing sensitive system information that should be restricted. This issue affects Jenkins versions up to 2.527 and LTS 2.516.2 or earlier, raising serious concerns about unauthorized data visibility and potential security breaches.
Affected Version(s)
Jenkins 0
Jenkins 0 < 2.387
Jenkins 2.516.3 < 2.516.*