Missing Permission Check in Jenkins Start Windocks Containers Plugin Affects Users
CVE-2025-64139
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 29 October 2025
What is CVE-2025-64139?
A security issue exists in the Jenkins Start Windocks Containers Plugin where a missing permission check could permit attackers with Overall/Read access to connect to a URL defined by the attacker. This vulnerability potentially exposes sensitive configurations and interactions within Jenkins, underscoring the need for prompt updates and stringent permission controls to safeguard against unauthorized access.
Affected Version(s)
Jenkins Start Windocks Containers Plugin 0 <= 1.4