Permission Check Flaw in Jenkins Affects User Data Access
CVE-2025-59474

5.3MEDIUM

Key Information:

Vendor

Jenkins

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-59474?

A significant vulnerability has been identified in Jenkins that fails to enforce proper permission checks for users lacking Overall/Read permissions. Specifically, those who do not possess the necessary permissions can exploit this flaw to access and enumerate agent names through the sidepanel executors widget, thereby exposing sensitive system information that should be restricted. This issue affects Jenkins versions up to 2.527 and LTS 2.516.2 or earlier, raising serious concerns about unauthorized data visibility and potential security breaches.

Affected Version(s)

Jenkins 0

Jenkins 0 < 2.387

Jenkins 2.516.3 < 2.516.*

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.