Permission Check Flaw in Jenkins Affects User Data Access
CVE-2025-59474
What is CVE-2025-59474?
A significant vulnerability has been identified in Jenkins that fails to enforce proper permission checks for users lacking Overall/Read permissions. Specifically, those who do not possess the necessary permissions can exploit this flaw to access and enumerate agent names through the sidepanel executors widget, thereby exposing sensitive system information that should be restricted. This issue affects Jenkins versions up to 2.527 and LTS 2.516.2 or earlier, raising serious concerns about unauthorized data visibility and potential security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins 0
Jenkins 0 < 2.387
Jenkins 2.516.3 < 2.516.*
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved