Jenkins 2.504

CPE Details

Jenkins 2.504
2.504
2025-04-22
10h44 +00:00
2025-04-22
10h44 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:jenkins:jenkins:2.504:*:*:*:-:*:*:*

Informations

Vendor

jenkins

Product

jenkins

Version

2.504

Software Edition

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-59476 2025-09-17 12h15 +00:00 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
5.3
Moyen
CVE-2025-59475 2025-09-17 12h15 +00:00 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).
4.3
Moyen
CVE-2025-59474 2025-09-17 12h15 +00:00 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.
5.3
Moyen