Cross-Site Request Forgery Vulnerability in Jenkins by CloudBees
CVE-2025-67639
3.5LOW
What is CVE-2025-67639?
A cross-site request forgery (CSRF) vulnerability has been identified in Jenkins, specifically impacting versions up to 2.540 and LTS 2.528.2. This issue allows malicious actors to potentially manipulate user sessions, enabling attackers to compel users into executing unintended actions within their accounts. Such vulnerabilities pose significant risks, especially in environments with extensive automation, making it crucial for users to apply necessary patches and take preventive measures to mitigate potential attacks.
Affected Version(s)
Jenkins 2.541
Jenkins 2.541
Jenkins 2.528.3 < 2.528.*